POST /bonus/claimVerifyWelcome offer from a device seen before
- Device linked to 4 prior claims
- Mobile proxy, new carrier IP
- Human input, no automation
Solution
Bonus abuse is when one person or group claims an incentive meant for a single new customer many times, using linked accounts to farm welcome offers, free bets, promo codes, cashback and referral rewards. Kavra checks every claim for the device, network and behavior shared with earlier accounts, so rewards reach real customers only.
POST /bonus/claimVerifyWelcome offer from a device seen before
Bonus abuse, also called promo abuse or incentive abuse, is the repeated claiming of an offer that the rules grant once per person, household or payment method. The offer is real and the terms are public. The abuse is in the identity: the same actor shows up as dozens of new customers so each one qualifies for the reward.
It is different from a lucky customer who reads the terms closely. A regular player who takes every reload bonus is using the product as designed. An operator who opens forty accounts to take forty welcome packages, then moves the proceeds into one wallet, is extracting value the offer was never priced for. Most of it runs on multi-accounting: the offer is the target, the extra accounts are the method.
Anything that pays a new or referred customer before they have spent their own money is on the list.
| Offer | Typical industry | How it is farmed |
|---|---|---|
| Welcome bonus and deposit match | iGaming and betting | Minimum deposit on each new account, wager through low-risk bets, withdraw |
| Free bets and odds boosts | Sportsbooks | Opposite outcomes backed across linked accounts so one side always wins |
| First-order discount codes | E-commerce and retail | New email per order, same card or address, goods resold |
| Referral rewards | Fintech, neobanks, delivery apps | Accounts refer each other in chains, both sides collect |
| Signup cashback and sign-on credit | Fintech and banking | Account opened, reward triggered, funds moved out, account abandoned |
| Free delivery and loyalty points | Food delivery, retail | Points pooled from throwaway accounts into one main account |
Professional abusers treat a promotion like a job with a shift plan. The steps are the same across industries.
Abusers study wagering requirements, minimum deposits, eligible markets and payout rules to find the cheapest path from bonus to cash. Forums and private groups share the math for new offers within hours.
Emails, phone numbers and sometimes borrowed or bought documents are lined up in advance. In iGaming, recruited third parties lend their names, a practice known as gnoming.
Each account gets its own browser profile, spoofed device and residential or mobile IP in the right country. The goal is to pass a one-account-per-person check that relies on cookies, IP or email.
The bonus is claimed and the conditions are met with the least risk: matched bets across accounts, small orders, the referral step a friend would do. Automation handles the repetitive parts.
Balances, points or goods flow to a few wallets, cards or drop addresses. By the time finance sees the cost per acquisition jump, the promotion is over.
The cost of bonus abuse is rarely one big loss. It is a promotion that looked profitable on paper and quietly was not. Marketing teams see strong signup numbers, product teams see activation, and the money leaves through accounts that never come back.
Look at claims as a group. A single claim rarely tells you much; a cluster does.
Different names and emails, but the same underlying device, even after the browser profile or fingerprint has been changed.
A burst of new accounts minutes after an offer goes live, each doing the minimum needed to qualify.
Deposits at the exact threshold, followed by the lowest-risk path to clear wagering, then an immediate withdrawal request.
Accounts that refer each other in a line or a star, all created from the same network range within a short window.
Each account appears on a different residential or mobile address, and the addresses belong to commercial proxy pools.
The same card, wallet, bank account or delivery address, with small variations like extra dots or a changed flat number.
Most promo controls check one attribute. Abusers change exactly that attribute for every claim.
| Defense | What it checks | How abusers get past it |
|---|---|---|
| One code per email | That the email is new | Aliases, catch-all domains and disposable inboxes |
| One offer per IP | The connection address | Residential and mobile proxies give each claim a fresh home IP |
| Cookie or local storage flag | That the browser has claimed before | Every new browser profile starts empty |
| CAPTCHA on signup | That a human is present | Abusers are human, and solving services cover the rest |
| Card or address matching | The payment or delivery detail | Virtual cards, prepaid cards and address variations |
| Post-promotion audits | Patterns after the fact | Money is already paid out and hard to claw back |
The best defense keeps offers generous for real customers and makes them unprofitable to farm. That means deciding at the moment of the claim, with evidence from several layers, and saving friction for the accounts that earn it.
How Kavra helps
Kavra assesses every signup and every claim with 3,000+ data points and tells your backend whether this is a new customer or an actor you have already paid.
Returning devices are recognized across accounts, so forty welcome bonuses from one operator show up as one cluster.
A device that changes its fingerprint between claims stays the same actor, with each rotation recorded as evidence.
Kavra measures real exit IPs of commercial residential and mobile proxy networks, so a fresh home IP per claim does not look fresh.
Antidetect profiles, emulators and virtual machines contradict themselves across layers, and Kavra checks for exactly that.
Each assessment is bound to the claim with a single-use, short-lived token, so a replayed or scripted request is refused and reported.
Your rules decide: pay the bonus, delay it, or step up. Start in observe-only mode to size the problem before changing a single offer.
FAQ
Something else? Talk to our team.
Bonus abuse is claiming an offer more times than the terms allow, usually by opening extra accounts, using other people's identities or coordinating with others to meet conditions without real risk. Taking every offer your single account qualifies for is not abuse. Opening new accounts to requalify for a first-time offer is.
They link accounts that share a device, network, payment method or behavior, then review the cluster rather than each account. Betting patterns matter too, such as opposite outcomes backed across accounts. Kavra supplies the device and network linking at signup and claim time, so operators can act before the bonus is released.
Yes. Most operators' terms allow them to void bonuses, confiscate winnings made with bonus funds and close linked accounts. In regulated markets, operators also have to show that promotions are applied fairly, which is another reason they act on clear evidence of linked accounts.
Pay referral rewards only after both accounts pass a check, and look for links between referrer and referee: shared device, network, payout details or signup timing. Delaying the reward until the referred customer shows real activity removes most of the profit from self-referral chains.
Done well, no. Kavra runs invisibly with no CAPTCHA puzzles or visible challenges. Most new customers are allowed straight through, and only claims with mixed evidence are held or stepped up. You can start in observe-only mode and see how many claims would be affected before enforcing anything.
They overlap. Promo abuse usually means repeatedly claiming a legitimate offer through fake or linked accounts. Coupon fraud can also include counterfeit or leaked codes used by people the code was never meant for. Both need the same answer: tie each redemption to a real actor and check it against earlier ones.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.