Two players at the same table can quietly work together to rob everyone else, or to move money between themselves as if the game were just a laundromat. Poker’s peer-to-peer format makes it uniquely exposed to this, because the house is not the counterparty — other players are.
Chip dumping and collusion are among the hardest forms of iGaming fraud to detect, because a single hand can look legitimate. The signal only emerges across many hands, many sessions, and the relationships between accounts.
The main collusion patterns
Poker collusion takes several recognizable forms:
- Chip dumping. One player intentionally loses to another to transfer value — laundering deposits, clearing a bonus, or settling an off-platform debt.
- Soft play. Colluders avoid betting hard against each other, effectively teaming up against non-colluding players at the table.
- Gnoming. One player runs multiple accounts (sometimes called grinding “gnomes”) that feed a main account or coordinate against opponents.
- Card sharing / real-time collusion. Two players on a shared channel reveal their hole cards to each other, gaining an information edge no honest player has.
Each pattern distorts the statistics of the game. Chip dumping shows value flowing consistently in one direction between the same accounts. Soft play shows suspiciously low aggression between specific pairs. Gnoming shows one operator behind several seats.
Device and network signals
The cheapest collusion rings are lazy about infrastructure, and that is where device intelligence pays off:
- Same device, multiple seats. A stable visitorId that appears on two or more accounts at the same table is a red flag no legitimate game produces.
- Shared network origin. Multiple “opponents” on the same home IP or subnet, especially during the same session, suggests one physical location.
- Coordinated session timing. Accounts that reliably log in together, play together, and leave together are behaving as a unit.
- Payment linkage. Value that dumps between accounts and then converges on a single withdrawal instrument exposes the purpose of the transfer.
Prynt supplies the persistent device identity and cross-account linkage that catch the shared-hardware and shared-network rings — the majority of casual collusion — before their hand histories even need forensic review.
When colluders are careful
Organized rings separate their devices, use different VPNs, and play from different cities, deliberately defeating naive IP matching. Here the evidence has to come from the felt: value-transfer patterns, soft-play pairs, and impossible fold/call decisions detected across large hand samples. Device intelligence still contributes by scoring the connection layer. A table where several seats arrive through anonymizing infrastructure warrants closer behavioral analysis, and our VPN and proxy detection flags that connectivity server-side so your game-integrity team knows where to look first.
Think of it as two complementary layers: device and network signals catch the sloppy rings cheaply, and behavioral hand analysis catches the disciplined ones. Neither alone is sufficient; together they cover the range.
Building a game-integrity response
Collusion enforcement has to be evidence-driven because the penalties — confiscated funds, account closure, seizure of a bankroll — are severe:
- Fingerprint every seat. Capture a visitorId at login so same-device-at-table conditions are caught in real time.
- Monitor value transfer. Track net chip flow between account pairs across sessions, not just single hands.
- Flag behavioral anomalies. Soft-play detection and abnormal fold-to-bet patterns feed the same case file.
- Review before you seize. Combine device linkage with hand-history evidence, and have a human confirm before confiscating funds.
Documented, multi-signal cases hold up when a player disputes a closure — and disputes are frequent, because the funds at stake are real.
Poker’s peer-to-peer nature will always attract colluders, but their coordination is also their weakness: they have to connect, and connections leave prints. Persistent device identity turns those connections into evidence. See the signals in our playground or review plans on our pricing page.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.