Professor
Professional
- Messages
- 1,750
- Reaction score
- 1,715
- Points
- 113
INTRODUCTION: WHY AGGREGATORS ARE THE NEW FRONTIER
Bro, the game has changed. While most carders are still burning through CVVs on basic Shopify stores and fighting Stripe Radar, the real money has moved to aggregator platforms — services that sit between you and the actual retailer, creating a perfect storm of liability ambiguity.This guide is about understanding why these platforms work, how to identify them, and what to do when you find one. We'll use BeyondStyle as the primary case study, but the principles apply to any merchant-of-record (MoR) or payment facilitator (PayFac) setup.
The core thesis: When a platform pays the merchant with their money and bills your card separately, the retailer's fraud detection never sees you. The aggregator's security is often an afterthought. And the liability gap is wide enough to drive a truck through.
PART 1: UNDERSTANDING THE PAYMENT ARCHITECTURE
1.1. Merchant of Record vs. Payment Facilitator
To exploit aggregators, you must understand the legal and technical frameworks they operate under.| Model | Who is the Legal Seller? | Who Handles Fraud Liability? | Who Handles Chargebacks? |
|---|---|---|---|
| Merchant of Record (MoR) | The MoR itself | The MoR | The MoR |
| Payment Facilitator (PayFac) | The Sub-Merchant | The Sub-Merchant | The Sub-Merchant |
Merchant of Record (MoR): The entity that takes legal and financial responsibility for a sale. The MoR becomes the seller of record: it charges the customer, remits applicable taxes, handles disputes, and absorbs fraud liability. The product is sold under the MoR's legal name.
Payment Facilitator (PayFac): A master merchant that aggregates many sub-merchants under its own merchant identification number (MID). The PayFac moves money, but the sub-merchant remains legally responsible for the sale, taxes, dispute responses, and regulatory requirements.
1.2. The Hybrid Model: Where Aggregators Live
Aggregators like BeyondStyle blur the line. They often operate as MoRs — they pay the underlying merchant with their corporate funds, then bill your card separately. This creates the exploit:- Retailer's Perspective: They receive a legitimate order from BeyondStyle, paid with BeyondStyle's corporate card. The retailer's fraud system never sees your card.
- Aggregator's Perspective: They process your card through their own (often weak) payment infrastructure. By the time they realize the card is dead, the order is already fulfilled.
- Liability Gap: The retailer has no liability (they got paid). The aggregator should absorb the loss, but their weak fraud detection means they often don't catch it in time.
1.3. Card Network Rules and MoR Models
Visa and Mastercard have different approaches to MoR models. Visa rules state that an entity is considered a merchant if it:- Represents itself as selling the goods or services to the cardholder;
- Uses its own name primarily to identify its store, website, or app; and
- Provides recourse to the cardholder in the event of a dispute.
Mastercard recognizes a "Platform Merchant" concept, requiring policies to collect and verify information about third-party sellers, implement fraud loss control measures, and understand liability for seller acts.
The Takeaway: Aggregators operating as MoRs take on significant liability. Their security is often the weakest link—and that's your entry point.
PART 2: CASE STUDY — BEYONDSTYLE (AND SIMILAR PLATFORMS)
2.1. What is BeyondStyle?
BeyondStyle is an AI-powered shopping platform connecting users to over 1,000 premium merchants and 10,000 brands. Born from BorderX Lab, it started as a cross-border shopping service and evolved into a hybrid aggregator.Trust Metrics:
- Trustpilot rating: 3.6–3.9/5 (mixed reviews)
- ScamAdviser: "very likely not a scam but legit and reliable"
- FranceVerif: "site à fiabilité douteuse" (doubtful reliability), flagged for dropshipping risks
- Domain age: 4+ years (registered 2020)
Mixed Signals: Some users report successful orders (Canada Goose jacket at 30% discount), while others report being charged without confirmation and unable to log in.
2.2. The Two Purchase Paths
| Option | What Happens | Security Level | Recommendation |
|---|---|---|---|
| "Buy Now" | Redirects to retailer's site | High (Saks, Bloomingdale's) | |
| "Buy with ShopAgent" | AI places order for you | Low (BeyondStyle) |
The second option is where the exploit lives. BeyondStyle pays the merchant first with their corporate methods, then bills your card separately.
2.3. Why This Creates a Security Hole
- Retailer's Blind Spot: The retailer sees a legitimate order from BeyondStyle, not from you. Their fraud detection never evaluates your card.
- Aggregator's Weakness: BeyondStyle's own fraud detection is basic—they accept almost any card with valid payment info.
- Delayed Processing: Payment is post-transaction. By the time BeyondStyle attempts to charge your card, the order is already in fulfillment.
- Liability Fog: Neither party has proper ownership of security. The retailer is protected (they got paid). BeyondStyle should be liable, but their weak systems mean losses slip through.
PART 3: SYSTEM SETUP FOR AGGREGATOR EXPLOITATION
3.1. Requirements (Minimal Compared to Direct Retailer Attacks)
| Component | Requirement | Notes |
|---|---|---|
| Card | Any valid CC, same country | Non-VBV not strictly required |
| Proxy | Basic residential | Nothing premium needed |
| Anti-Detect Browser | Basic configuration | Octo, Dolphin, or AdsPower |
| Drop Address | Geographically logical | Matches cardholder region |
| Any working email | Can use cardholder's email | |
| Account | New or existing | Easy to create |
Why Requirements Are Low: The aggregator's weak fraud detection means you don't need premium proxies, aged accounts, or Non-VBV BINs. The retailer's security — which would normally block you — never sees your card.
3.2. Step-by-Step Setup
Step 1: Create Account
- Navigate to the aggregator platform (e.g., BeyondStyle.us)
- Sign up with any email
- Verify if required (some don't require verification)
Step 2: Configure Browser
- Launch anti-detect browser (Octo, Dolphin, AdsPower)
- Create new profile
- Assign residential proxy matching cardholder region
- Verify: WebRTC off, timezone matches proxy, language consistent
Step 3: Prepare Card and Address
- Verify card is alive (checker or small test)
- Ensure drop address is geographically logical with billing
- Example: Card from NY → Drop in NY or nearby
PART 4: THE EXPLOITATION PROCESS
4.1. Step-by-Step Execution
Step 1: Find Target Item
- Search for luxury items (Prada, Gucci, Alexander Wang, etc.)
- Start with items in the $200–$500 range for testing
- Verify the item is available through the aggregator
Step 2: Select the Correct Purchase Path
- ALWAYS use "Buy with ShopAgent" (or equivalent)
- NEVER use "Buy Now" (redirects to retailer's secure site)
Step 3: Enter Payment Details
- Enter card number, expiry, CVV
- Enter cardholder name (matching card)
- Enter billing address (matching card)
- Enter manually — no copy-paste
Step 4: Configure Shipping
- Select drop address
- Ensure geographical logic with billing address
- Confirm order
Step 5: Post-Order Behavior
- DO NOT check status obsessively
- Wait for confirmation or cancellation
- If cancelled: switch address and card, try again
- If confirmed: wait for shipping notification
4.2. Why This Works
The aggregator's business model requires them to pay the merchant first with their corporate funds. Your card is billed separately. By the time they attempt to charge your card and discover it's dead, the merchant has already processed and shipped the order.
PART 5: ERRORS, RISKS, AND FIXES
5.1. Common Errors
| Error | Cause | Fix |
|---|---|---|
| Order Cancelled | Address blacklisted OR card declined | New address + new card |
| Order Stuck | Manual review OR merchant delay | Wait 24-48h, don't obsess |
| Item Not Shipped | Merchant cancelled OR stock issue | Contact support, request refund |
| Account Blocked | Multiple cancellations OR suspicious activity | New account, proxy, email |
| Card Declined | Insufficient funds OR dead card OR bank block | Check card, try different card |
5.2. Risk Assessment
| Risk | Probability | Mitigation |
|---|---|---|
| Order cancellation | Medium | Change address/card after each attempt |
| Account suspension | Medium | Rotate accounts, don't reuse |
| Card decline | High | Verify cards before use |
| Address blacklist | Medium | Rotate drop addresses |
| Legal exposure | Low | Use proxy, never real data |
5.3. OPSEC Rules
- Always use residential proxy matching card region
- Never use real personal data
- Rotate accounts after each order
- Rotate drop addresses
- Don't brag about successes
- Keep detailed logs
- Use anti-detect browser for isolation
- Don't work from home
PART 6: AGGREGATOR VS. DIRECT RETAILER — COMPARISON
| Criterion | Aggregator (MoR) | Direct Luxury Retailer |
|---|---|---|
| Security Level | Low | Very High |
| 3D Secure | Often None | Often Required |
| Card Requirements | Any Valid CC | Non-VBV + High Reputation |
| Proxy Requirements | Basic Residential | Premium Residential |
| Account Requirements | Any | Aged with History |
| Success Rate | 40–60% | 10–20% |
| Risk Level | Low | High |
| Time to Result | 2–5 Days | 1–2 Weeks |
PART 7: COMPLETE CHECKLIST
Before Starting:
- □ Valid card (any, same country)
- □ Basic residential proxy configured
- □ Drop address (geographically logical)
- □ Email for account
- □ Aggregator account created
- □ Anti-detect browser configured
Before Ordering:
- □ Item selected ($200–$500 for test)
- □ "Buy with ShopAgent" selected
- □ Card details ready
- □ Billing address matches card
- □ Drop address logical
- □ Proxy active
- □ Time matches region
After Ordering:
- □ Order confirmed
- □ Do not check status obsessively
- □ Wait for notification
- □ If cancelled: new address + new card
- □ If success: log result, rotate for next order
PART 8: KEY TAKEAWAYS
The aggregator exploit is not about brute force — it's about understanding liability structures and exploiting gaps in responsibility.Core Principles:
- MoR Liability Gap: When an aggregator pays the merchant first and bills you separately, the retailer's fraud detection never sees your card.
- Weak Aggregator Security: Aggregators prioritize convenience over security. Their fraud detection is often basic.
- Delayed Processing: Post-transaction billing gives you a window of opportunity.
- Low Requirements: Basic cards, basic proxies, basic accounts — because the retailer's security is bypassed entirely.
- Rotate Everything: Accounts, addresses, cards. Never reuse.
The Playbook:
- Identify MoR/PayFac platforms (aggregators, marketplaces)
- Always use the aggregator-mediated purchase path
- Start small, rotate everything
- Understand that this window will close — exploit it while it's open
GLOSSARY
| Term | Definition |
|---|---|
| MoR | Merchant of Record — legal entity responsible for a sale |
| PayFac | Payment Facilitator — aggregates sub-merchants under one MID |
| MID | Merchant Identification Number |
| CVV | Card Verification Value |
| AVS | Address Verification System |
| 3DS | 3D Secure — authentication protocol |
| Drop | Address for receiving goods |
Good luck, bro. If anything — ask.