POST /bonus/claimBlockedAntidetect profile, same actor as 6 accounts
- Claims a Mac, renders like Windows
- Fingerprint rotated 9 times in 7d
- Residential proxy exit
Detection
An antidetect browser is a modified browser that runs many isolated profiles, each reporting a different device: screen, graphics card, fonts, timezone, language and cookies, usually behind its own proxy. Dozens of commercial products sell this as a subscription. Kavra detects them by the contradictions each fake profile leaves across layers.
POST /bonus/claimBlockedAntidetect profile, same actor as 6 accounts
An antidetect browser is a desktop app, usually built on the same engine as Chrome or Firefox, that lets one person run many separate browser profiles side by side. Each profile has its own cookies and storage, its own proxy, and its own made-up device. When a website asks the browser what screen, graphics card, fonts, language or timezone it has, the profile answers with the values from its fake device, not the real laptop underneath.
There are dozens of commercial products. Most sell by the number of profiles, include team sharing so several operators can work the same accounts, and offer an automation interface so scripts can open profiles and click through pages. For your site, the result is simple: one operator can look like hundreds of unrelated customers in different cities. The underlying technique is covered in our guide to fingerprint spoofing and rotation.
Each profile is a costume. These are the parts a site can see, and how the tool dresses them up.
| What the site reads | What the profile does | Why it matters to the operator |
|---|---|---|
| Operating system and browser version | Reports a chosen system, for example Windows 11 or macOS, and a recent browser version | Blends in with the most common real visitors |
| Screen size and window | Picks a resolution and window size from a list of real devices | Stops sites from grouping profiles by one odd screen |
| Graphics card and drawing output | Reports a different graphics card and adds small noise to drawn images | Breaks canvas fingerprinting and similar checks |
| Fonts, audio and hardware | Changes the font list, audio output, number of processor cores and memory | Makes each profile look like separate hardware |
| Timezone, language and location | Matches them to the country of the attached proxy | Keeps the story consistent with the IP address |
| Cookies and storage | Keeps a separate, clean storage per profile | Each account looks like a first visit from a new browser |
| IP address | Routes each profile through its own proxy, often residential | Hides the fact that all profiles share one internet connection |
The same tool serves fraud rings and ordinary agencies. What matters is what the profiles do on your site.
| User | What they do with it | What it means for you |
|---|---|---|
| Multi-accounters | Run many accounts per person to dodge one-account rules and bans | Duplicate users, skewed data, returning banned actors |
| Bonus and promo abusers | Claim welcome offers, free bets or first-order discounts many times | Promo budget paid to one person again and again |
| Affiliate and referral fraudsters | Create fake referred users to collect commissions or referral payouts | Paying partners for customers who do not exist |
| Ad and seller account farmers | Keep many ad, seller or social accounts alive after bans | Fake listings, fake reviews, recycled bad actors |
| Social media managers and agencies | Log in to client accounts without mixing sessions | Legitimate, but looks like one device with many accounts |
| QA, ad verification and research teams | Test sites and ads as users from other countries and devices | Legitimate test traffic you may want to label, not block |
The pattern is the same for a sportsbook, a fintech signup bonus or an affiliate program.
The operator generates dozens of profiles, often from templates that copy the most common real devices in the target country.
Every profile gets its own residential or mobile proxy so its IP address matches its claimed city and carrier.
Profiles browse, accept cookies and sign up at a human pace, sometimes over days, so the accounts look lived in.
Scripts drive the profiles through signup, email checks and claims, using the tool's built-in automation interface.
Rewards are claimed and moved out. Flagged profiles are thrown away and replaced with fresh fingerprints the same afternoon.
Antidetect browsers are built to beat exactly the checks most sites rely on. They are not scripts pretending to be a browser: they are real browsers, driven by a real person much of the time, so the page loads, runs and behaves like any other visit.
The weak spot is scale. Faking one value is easy. Keeping every value consistent with every other layer, on every page, for hundreds of profiles on the same hardware, is very hard.
A profile can lie on one layer. Detection works by checking whether the layers agree with each other.
| Layer | What the profile claims | What gives it away |
|---|---|---|
| Device and graphics | A MacBook with an Apple graphics chip | Drawing and 3D output that matches a Windows PC with a different graphics card |
| Browser integrity | An untouched browser of a given version | Traces of patched functions, or features that do not match the claimed version |
| Fonts and system | A standard Windows font set | Text that renders the way another operating system renders it |
| Network | A home user in Chicago on local broadband | An exit from a commercial proxy pool, with a connection that looks like a different system than the browser claims |
| Behavior | A new person reading and typing | The same typing rhythm, field order and pauses as other "new" profiles |
| Identity and history | A device never seen before | The same underlying machine seen under many fingerprints and accounts |
Not every antidetect profile is an attack. Agencies manage client social accounts this way, QA teams test localized pages, and some people use these tools for privacy. Blocking the tool on sight hurts them and teaches fraudsters nothing. Decide by what the profile is trying to do and what it is linked to.
Use this list to review your current setup. Each item closes a gap these tools are designed to use.
How Kavra helps
Kavra analyzes 3,000+ data points on every visit and checks whether the device, browser, network and behavior tell the same story.
Antidetect profiles are caught by what they claim versus how they actually render and run.
Kavra looks for signs that the browser itself was modified, not only for suspicious values.
Kavra's own edge network sees the actual connection and compares it with the device the browser claims to be.
A machine that changes fingerprints stays one actor with a count of rotations, not a stream of new visitors.
Profiles that share a machine, network or behavior are grouped, so a ring of accounts shows up as one cluster.
Each verdict lists the findings behind it. Allow agencies, verify mixed cases and block rings with your own rules.
FAQ
Something else? Talk to our team.
It lets one person run many browser profiles that each look like a separate device and location. Fraud rings use it for multi-accounting, bonus abuse, affiliate fraud and ban evasion. Legitimate users include social media agencies managing client accounts, QA teams testing localized sites and ad verification teams. The tool is the same; the intent differs.
In most countries, owning or using an antidetect browser is legal. What is often not allowed is how it is used: breaking a platform's one-account rule, claiming a bonus many times or faking referrals violates terms of service and can amount to fraud. That is why platforms judge the activity, not just the tool.
Yes, though not by reading the fingerprint alone, because these tools control those values. Detection works by comparing layers: whether the claimed device renders like that device, whether the browser shows signs of modification, whether the network matches the story and whether the same machine keeps appearing under new fingerprints.
No. A VPN changes only your IP address and route. An antidetect browser changes what the browser says about the device, keeps separate cookies per profile and usually pairs each profile with its own proxy. Fraudsters often combine both, which is why detection needs to check device and network together.
Usually not. Blocking the tool on sight catches some agencies and privacy users and gives fraudsters a clear signal to adapt. A better approach is to record the detection, link it to other accounts, and act at high-value moments such as bonus claims or payouts, with verification for mixed evidence and blocks for clear rings.
No. Randomizing values on every visit makes the fingerprint unstable, and an unstable fingerprint on a returning machine is itself unusual. Real devices change rarely and slowly. A machine that shows a new fingerprint each session is a signal worth tracking, not an invisible visitor.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.