An issuer’s approval means the card is real and funded. It says nothing about whether the person entering it stole it. That gap is where card-not-present fraud lives, and it is why a clean authorization is not a clean transaction.
Device intelligence closes the gap by profiling the buyer rather than the card. A stolen card in a fraudster’s hands leaves a device and network trail that rarely matches a real cardholder’s.
What a stolen-card checkout looks like
The card details are perfect because they were bought or phished. Everything around them is off:
- The device is brand new to your store; the real cardholder never shopped here from it.
- The network hides origin via VPN, proxy, or a datacenter IP.
- The geography is inconsistent: a billing address in one country, a device timezone and IP in another.
- The session shows automation or scripted checkout, or an emulator.
- The behavior is rushed and goal-directed: straight to an expensive, resellable item with expedited shipping.
None of these is proof alone. Together they form a profile that legitimate buyers seldom produce.
Device signals that expose the fraudster
Prynt anchors the session with a stable visitorId, then layers server-side Smart Signals that speak directly to stolen-card risk:
- Proxy, VPN, and datacenter detection flags the network hiding that so often accompanies stolen cards.
- Geolocation and impossible-travel signals catch billing-versus-device mismatches and physically impossible movement between sessions.
- Bot and automation flags expose scripted checkout draining a batch of stolen numbers.
- Emulator, root, and jailbreak signals surface the manipulated devices favored by fraud operations.
- Device velocity reveals one machine cycling many cards or identities.
Because these are computed server-side and returned to your backend, the verdict is trustworthy even against an attacker who tampers with the client.
Scoring the transaction, not blocking blindly
The goal is a risk score you can act on proportionally, not a hair-trigger block that torches conversion. Combine positive and negative signals:
- Recognition — is this a device that completed prior undisputed orders? Strong reassurance.
- Network risk — proxy, VPN, datacenter, or Tor exit node.
- Geographic coherence — do billing, IP, and device timezone agree?
- Automation — human session or scripted?
- Velocity — how many cards or accounts has this device touched?
A recognized, residential, coherent, human, low-velocity device clears frictionless even on a first purchase. A new, proxied, geographically incoherent, automated device should face a step-up challenge or a decline. Our payment fraud detection guide shows how to translate this into thresholds.
Handling the ambiguous middle
Most transactions are not obviously good or bad. For the middle band, step up rather than block: trigger a 3DS challenge, request additional verification, or hold for manual review on high-value orders. This preserves conversion for genuine customers on new devices (travelers, gift buyers) while forcing the fraudster to clear a bar they usually cannot.
The reputation-network advantage
A stolen card is often run across many merchants in a short window. When a device tests or spends stolen cards at one Prynt-protected merchant, that history travels. The same device arriving at your checkout is pre-flagged, so you can decline or challenge on the first attempt rather than after the chargeback teaches you the lesson.
Measuring detection quality
Track the fraud capture rate (share of chargeback-confirmed fraud your rules flagged at checkout) against the false-decline rate on good customers. The best programs raise the first while holding the second, because device signals let them distinguish an unfamiliar-but-genuine buyer from a genuine fraudster. Watch stolen-card chargebacks specifically, and expect them to fall two to four weeks after tightening device-based rules.
A valid card is table stakes for fraud, not a defense against it. Profile the buyer behind the card, and the stolen ones start to stand out well before the dispute arrives.
Score a checkout device yourself in the playground and see the stolen-card signals in action.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.