What denial of inventory is
Most online stores and booking systems reserve an item the moment someone starts to buy it. A seat on a flight is held while the passenger enters their details. A concert ticket is held for a few minutes at checkout. A limited product is reserved when it lands in the cart. That hold is fair to the buyer, and it is exactly what denial of inventory abuses.
The OWASP Automated Threats to Web Applications project lists it as its own threat, separate from scalping, because the bot does not need to buy anything to do damage. In airline and travel circles, the same practice is called seat spinning.
How a denial of inventory attack works
- 01
Find the hold
The attacker learns how long the site keeps an item reserved in a cart or booking before releasing it.
- 02
Reserve at scale
Bots open many sessions, often through residential proxies and throwaway accounts, and add the target items or seats.
- 03
Stall the payment
Each session stops at the payment step, or submits a card that fails, keeping the hold alive as long as possible.
- 04
Repeat
When holds expire, the bots grab the items again within seconds, before any real customer can.
Why attackers do it and what it costs
Feeding scalpers
Stock is held until the scalper's own accounts are ready to buy, or released to them in a controlled way.
Blocking competitors
A rival holds seats, rooms or delivery slots so a business looks full, or to push prices on its own inventory.
Moving prices
On dynamic pricing systems, fake demand makes the remaining stock look scarce and the price rises for everyone.
Lost sales and trust
Real customers see sold out, leave, and buy elsewhere. Stock that reappears unsold later damages trust in the brand.
How to detect and prevent it
The pattern shows up in data that most teams do not watch closely: carts and reservations that never convert, the same items held again seconds after release, many holds from new accounts and fresh sessions, and failed payments used to extend holds. Airlines and ticketing platforms can see it as seat maps that fill and empty in cycles.
- Shorten holds for anonymous or new sessions, and extend them only for trusted customers.
- Limit how many holds one actor can keep, counted by device and behavior, not just by account.
- Assess the add-to-cart or hold request itself, not only the final payment.
- Track holds that never convert, and link them back to shared devices and networks.
Kavra assesses every cart, hold and checkout request and tells your backend whether it comes from a real customer or from automation hidden behind proxies and spoofed devices, so holds go to people who intend to buy. See scalping and inventory hoarding for the full approach, and how it applies in travel and ticketing.