POST /cart/add?drop=spring-releaseBlockedBot actor running 27 accounts in one drop
- Scripted checkout, no browsing
- Same device as 26 other carts
- Mobile proxy, new IP per account
Solution
Scalping is when resellers use bots to buy limited products, such as sneakers, consoles or event tickets, faster than any person can, then resell them at a markup. Related bots hold stock in carts to deny it to others. Kavra spots the automation and the one actor behind many accounts, so real customers get a fair chance.
POST /cart/add?drop=spring-releaseBlockedBot actor running 27 accounts in one drop
Scalping is buying limited items to resell them at a higher price. It is as old as ticket touts outside a stadium. What changed is speed and scale: a reseller with a bot and a few hundred accounts can buy a large share of a sneaker drop, a console restock or a concert on-sale in the seconds after it opens, while real fans are still waiting for the page to load.
A close relative is inventory hoarding, also called denial of inventory. Here bots add items to carts or hold seats without paying, which takes stock off the market for the length of the hold. Some operators do it to buy later, some to push buyers toward their own resale listings, and some to hurt a competitor.
Scalping is an organized business, with tools sold by subscription and tutorials for each major store.
The operator creates or buys many accounts in advance, each with its own email, phone, address variation and payment card, to get around one-per-customer limits. This is fake account creation with a purpose.
Monitors scrape product pages, stock APIs and social channels to learn the exact drop time and product IDs, sometimes before the public page goes live.
Each account is paired with a residential or mobile proxy in the right country, so hundreds of buyers seem to come from hundreds of homes.
At release, the bot joins the queue, adds to cart and checks out through every account at once, often calling the store's endpoints directly instead of loading pages.
Items are listed on resale marketplaces, often before the original order has shipped, at prices real fans could not get at retail.
Anything scarce, dated or hyped attracts bots. The tactics barely change between a sneaker drop and a stadium on-sale.
| Where | What bots target | What goes wrong |
|---|---|---|
| Sneakers and streetwear | Limited drops, raffles, collaborations | Fans lose, brand hype turns into resale profit |
| Consoles and electronics | Restocks of high-demand hardware | Stock gone in seconds, support flooded with complaints |
| Travel and ticketing | Concert and sports on-sales, seat holds | Seats held or resold at markups, sold-out shows with empty seats |
| E-commerce and retail | Collectibles, trading cards, seasonal toys | Per-customer limits ignored, loyal customers leave |
| Restaurants and events | Reservations and timed slots | Tables booked and resold, no-shows |
Scalping looks harmless on a sales report: the item sold at full price. The damage shows up elsewhere.
Look at the release as a whole, not order by order. Bot traffic shows up as clusters and timing that crowds of real fans do not produce.
Orders complete faster than a person can type an address, with no product page view before add to cart.
Different names and emails that share devices, networks, card ranges or slightly altered shipping addresses.
Stock sits in carts or holds until they expire, then is added again by the same actors.
Thousands of new residential and mobile addresses arrive in the minute before release, many from proxy networks.
Waiting-room entries from a burst of fresh sessions that joined at the same instant.
"Unit 1", "Apt 1" and misspelled street names used to get around one-per-address limits.
Each measure assumes one buyer equals one account, one session or one IP address. Scalpers break exactly that assumption.
| Measure | The idea | How bots get past it |
|---|---|---|
| Purchase limits per account | One pair per customer | Account farms turn one customer into hundreds |
| Waiting rooms and queues | First come, first served | Bots join with hundreds of sessions and take the best places |
| CAPTCHA at checkout | Only humans pass | Solving services and human farms clear it; fans lose seconds |
| Raffles instead of sales | Luck, not speed | More accounts mean more entries, so bots still win more |
| IP rate limits | One IP is one buyer | Residential and mobile proxies give every account its own IP |
Fair drops depend on two questions answered at the right moment: is this a person, and is this person already buying under other names? A practical checklist:
How Kavra helps
Kavra assesses every queue entry, cart and checkout with 3,000+ data points and tells you who is a real fan and who is running the bots.
Sneaker bots, headless browsers and scripts calling your cart API are caught by contradictions between what they claim and how they behave.
Returning devices are recognized across accounts, so a farm of buyers shows up as one operator and your limits apply per actor.
Real exit IPs of commercial residential and mobile proxy networks are measured directly, so rotating addresses do not create new buyers.
Waves of new devices, shared infrastructure and velocity anomalies around a release are flagged as a coordinated campaign.
Kavra runs invisibly. When evidence is not conclusive, more invisible checks run, and real buyers never have to solve anything.
Choose cautious, balanced or strict presets per drop, and decide in your backend whether to allow, verify or refuse.
FAQ
Something else? Talk to our team.
For event tickets in many places, yes. In the United States, the BOTS Act makes it illegal to get around a ticket seller's security measures or purchase limits, and some other countries have similar laws. For sneakers and other goods, bots are usually legal but break the store's terms, which lets retailers cancel orders and close accounts.
A sneaker bot automates the checkout for many accounts at once. It watches for the release, then joins the queue, adds the item to cart and pays in each account within seconds, usually through a different residential proxy per account. Many are sold by subscription with presets for specific stores.
Denial of inventory is when bots add items to carts or hold seats and bookings without buying, keeping stock unavailable to real customers until the hold expires. It is common in ticketing, travel and limited retail drops. Stopping it means spotting automated holds early and releasing that stock quickly.
They slow the crowd but do not tell bots from people. A scalper can enter the queue with hundreds of sessions and still get more places than any fan. Queues work best when paired with bot detection at entry, so automated sessions and linked accounts are removed before they reach the front.
Limits per account or card are easy to dodge with account farms and prepaid cards. Apply the limit per actor instead: link accounts through shared devices, networks and behavior, then count purchases for the whole cluster. Kavra provides that linking, and your backend enforces the limit.
It should not. Kavra's script loads asynchronously and never blocks the page, and the assessment runs in the background while the customer shops. Most people never see a challenge. Only sessions with mixed evidence get extra invisible checks or the step-up your rules choose.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.