Presale and early-access codes exist to reward loyal fans with a head start. But when a code is just a string tied to an account, bots farm them by the thousand and the early window fills with scalpers instead of the people it was meant for.
The fix is to stop treating a code as proof of a person and start binding it to the real device that earned it.
How code farming works
Presale systems usually gate the early window behind a code delivered by email, loyalty status, or a signup. Bots exploit every delivery path. They mass-register accounts to harvest signup codes, scrape codes leaked in bulk, or use stolen loyalty accounts to mint legitimate ones.
Once a scalper holds a pile of working codes, they either resell them on secondary markets or feed them straight into auto-checkout tasks. Either way the early access that was supposed to reward one fan gets multiplied across an operator’s entire fleet of accounts.
Why account-only checks fail
A code validated only against an account assumes the account is a person. It is not. Accounts are cheap to create and easy to steal, so the operator simply spins up or takes over as many as the codes require. The code changes hands freely because nothing ties it to who earned it.
This is why presale windows so often feel rigged: the codes were real, but the entities holding them were bots. The missing link is a durable identity for the redeemer.
Binding access to a real device
Prynt supplies a stable visitorId that persists across cookies, IPs, and user agents, so you can attach a real device identity to the moment a code is earned and again to the moment it is redeemed.
- Bind at issuance so the code is associated with the device that legitimately earned it.
- Verify at redemption so a code redeemed from a different, unrelated device raises a flag.
- Detect automation with Smart Signals that catch headless browsers and frameworks farming or redeeming codes.
- Flag proxies and known scalper devices so farmed codes cannot be quietly cashed in from a relay.
When redemption must match, or at least correlate with, the device that earned the code, a resold code becomes far less useful because the buyer’s device does not line up. Our bot detection overview shows how these signals stack into one decision.
Designing an abuse-resistant presale
Treat the code as one factor and the device as the anchor.
- Require a verified visitorId at signup or loyalty enrollment, and deduplicate so one device cannot farm many codes.
- Bind each issued code to the earning device and record that association.
- At redemption, verify the visitorId and scrutinize codes redeemed from a device with no link to issuance.
- Score redemption with Smart Signals and hold or decline automated or high-suspicion attempts.
- Keep a reputation list so devices caught farming one presale start the next flagged.
Deduplicating at issuance is what caps the supply of farmable codes; verifying at redemption is what defeats the resale of the few that leak. Together they close both ends of the pipeline.
Design the device binding to tolerate real life, though. Fans legitimately switch phones, clear browsers, or redeem on a laptop after signing up on mobile, so a rigid device match will generate false positives on exactly the loyal customers you meant to reward. The better approach is correlation rather than a hard equality check: treat a redemption from a device unrelated to issuance as a signal to weigh alongside automation flags and proxy detection, not as an automatic rejection. That way a genuine fan on a new phone sails through while a scalper redeeming a farmed code from a flagged, automated device gets stopped.
Measuring a clean presale
Compare codes issued to unique verified devices, and redemptions to the devices that earned them. A healthy presale shows codes spread across many distinct devices and redemptions largely matching issuance. Abuse shows codes clustered on few devices or redeemed from devices unrelated to who earned them.
Watch resale channels too. If presale codes stop appearing for sale, or stop working when bought, the binding is holding and real fans are getting their head start.
A presale code should prove loyalty, not act as a bearer token bots can farm. Anchoring it to a real device restores that promise. Start free and test your code flow in the playground to see how quickly farmed redemptions surface.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.