POST /signupBlockedSame actor as 13 other accounts
- Antidetect browser profile
- Residential proxy exit
- Linked to 13 accounts
Solution
Multi-accounting is when one person or group creates and runs several accounts on the same platform to claim repeat bonuses, bypass limits, manipulate outcomes or return after a ban. Kavra links those accounts back to the device, network and behavior they share, even when each one looks new.
POST /signupBlockedSame actor as 13 other accounts
Multi-accounting means one real person, or one organized group, controlling more than one account on a service that expects one account per person. On its own, a second account is not always fraud. It becomes fraud when the extra accounts exist to take something the rules give only once: a welcome bonus, a free trial, a referral reward, a first-order discount, a voting right or a fresh start after a ban.
Modern multi-accounting is rarely manual. Operators run tens or hundreds of accounts from one laptop with an antidetect browser, route each one through a different residential proxy, and script the signup flow. Every account looks like a different person, on a different device, in a different city.
Most campaigns follow the same playbook, whether the target is a sportsbook bonus or a SaaS free tier.
The operator buys or generates emails, phone numbers and sometimes documents. Disposable inboxes and virtual numbers make each identity cheap.
Each account gets its own browser profile with a spoofed device: different screen, graphics card, fonts, timezone and language. Emulators and virtual machines do the same on mobile.
Traffic for each profile exits through a different residential or mobile IP address, usually in the same country as the target audience.
Scripts or automation frameworks fill in forms, verify emails and claim the reward, often in bursts timed around a promotion.
Rewards are withdrawn, consolidated into one account, resold, or used to tilt a result, such as matched bets, fake reviews or ranking manipulation. By the time the pattern shows up in reports, the budget is already spent.
Any business that gives something of value to a new account is a target. In iGaming, it drains welcome bonuses and free bets through what the industry calls bonus abuse and gnoming. In fintech, duplicate accounts collect signup rewards and hide mule activity. On marketplaces, they post fake listings, leave fake reviews and return after bans. In SaaS and AI products, they farm free credits and trials. In e-commerce, they stack first-order discounts.
The technique is the same everywhere. What the operator is after changes.
| Industry | What multi-accounters farm | Where to check |
|---|---|---|
| iGaming and betting | Welcome bonuses, free bets, odds boosts, arbitrage limits | Signup, bonus claim, withdrawal |
| Fintech and banking | Signup rewards, referral payouts, mule accounts | Onboarding, first transfer |
| Marketplaces | Fake listings, fake reviews, ban evasion | Seller signup, listing, review |
| SaaS and AI products | Free trials, free credits, API quotas | Signup, trial start, API key creation |
| E-commerce and retail | First-order discounts, limited drops, loyalty points | Account creation, checkout |
| Travel and ticketing | Ticket limits per customer, fare holds | Account creation, cart, checkout |
No single signal proves it. Patterns across accounts do.
A browser claims one graphics card and screen, but renders like another. Profiles that differ on the surface behave identically underneath.
Every signup comes from a different home IP address in the right country, yet the addresses belong to commercial proxy pools.
The same returning visitor shows up with a new fingerprint on each visit. Rotation is itself a signal.
Forms filled in the same order at the same speed, with pasted values and no hesitation, across many new accounts.
Spikes of new accounts right after an offer launches, clustered by time, network or email pattern.
Different accounts withdraw to the same wallet or card, or refer each other in chains.
Each classic check covers one layer. Multi-accounting tools are built to pass exactly that layer.
| Defense | What it checks | How multi-accounters get past it |
|---|---|---|
| Email and phone verification | That the contact exists | Disposable inboxes and virtual numbers cost cents |
| IP blocklists | Known bad addresses | Residential proxies rotate through real home IPs |
| Cookies and local storage | A returning browser | Each antidetect profile starts with empty storage |
| Basic device fingerprinting | What the browser reports | Antidetect browsers rewrite every reported value |
| CAPTCHA | That a human is present | Solving services and a human operator pass it easily |
| KYC at signup | A real identity document | Adds friction for everyone, and stolen or borrowed identities still pass |
The goal is to recognize the same actor across accounts without adding friction for the honest majority. That takes evidence from several layers at once, checked for contradictions, and a decision at the moment it matters: before the reward is granted.
How Kavra helps
Kavra analyzes 3,000+ data points on every visit and links accounts that share an actor, then tells your backend what it found, in plain language.
Returning devices are recognized across visits and accounts, so one actor behind many signups shows up as one cluster.
When a device changes its fingerprint but stays the same actor, Kavra keeps one identity and flags the rotation.
Antidetect profiles, emulators and virtual machines are caught by the contradictions between what they claim and how they behave.
Kavra measures real exit IPs of commercial residential and mobile proxy networks, on top of public reputation feeds.
Every layer is weighed together, and models keep learning from new fraud patterns without adding friction for real users.
Allow, verify or block with your own rules. Start in observe-only mode to see every linked account before acting.
FAQ
Something else? Talk to our team.
Usually it is not a crime by itself, but it breaks the terms of service of most platforms that offer bonuses, trials or one-account-per-person rules. It can become fraud when accounts are used to obtain money, rewards or credit under false pretenses, which is why operators close the accounts and withhold the rewards.
By linking accounts through evidence they share and cannot easily change together: the real device behind a spoofed profile, the network it uses, how it behaves and its history. Kavra checks these layers for contradictions on every visit and groups accounts that belong to the same actor.
They hide it from checks that trust what the browser reports. They rewrite the device values a page can read, but they struggle to keep every layer consistent at once. Kavra looks for those inconsistencies, so a profile that looks new on the surface can still be linked to the actor behind it.
It should not. Families sharing a home network or a device are normal, so good detection weighs many signals instead of blocking on one. Kavra runs invisibly, never shows CAPTCHA puzzles, and lets you verify or delay only the risky few while everyone else signs up without friction.
Assess at signup and act before value leaves. Checking at signup stops rewards from being granted to linked accounts, while a second check at bonus claim or withdrawal catches accounts that looked clean at first and later joined a ring.
Multi-accounting is the technique: many accounts run by one actor. Bonus abuse is one of the main reasons to do it: claiming a welcome offer, free bet or promo code many times. Most bonus abuse relies on multi-accounting, but multi-accounting is also used for ban evasion, review fraud and vote manipulation.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.