Brazil moved from an unregulated betting market to a licensed one under Law 14.790/2023, with the regulated regime in force since January 2025. Licensed operators run on .bet.br domains under rules issued by the Secretaria de Prêmios e Apostas (SPA) of the Ministry of Finance. Those rules put identity at the center: players must be adults, verified against a valid CPF with facial recognition, with one account per person, and money can only move between the betting account and a payment account in the player’s own name.
On paper, that closes the door on multi-accounting. In practice, it changes the shape of the problem. This post looks at the abuse that survives strong identity checks and the device-level controls that catch it.
What strong KYC solves, and what it does not
CPF verification and facial recognition answer one question well: does this person exist, and are they the one opening the account? They make synthetic identities and borrowed documents much harder to use at onboarding.
They do not answer: who is operating this account a week later? and how many verified accounts does this one operator control? Abuse in a strongly identified market moves to exactly those gaps.
Patterns that pass identity checks
Feeder accounts
A feeder (or “gnome”) account belongs to a real person who agreed, often for a small payment, to open it and pass verification. The operator then controls it. Each feeder has a real CPF, a real face, and a payment account in their own name, so every check passes. The operator uses a group of feeders to multiply limits, spread arbitrage bets across accounts, or chip-dump in peer-to-peer games. Our post on gnoming detection covers the betting-pattern side of this.
Shared devices
The operator rarely has a phone per feeder. Accounts are run from a handful of devices: one phone with an app-cloning tool, an emulator farm on a PC, or a browser profile per account on one laptop. The person behind each account differs; the device does not.
Promotional abuse after the bonus ban
The law bars operators from granting advances, bonuses or prior advantages to place bets, which removed the classic welcome bonus from the regulated market. Promotions did not disappear entirely: operators still run offers for existing players within what the rules allow. Wherever an offer gives a per-account benefit, multiple accounts multiply it, and the same device patterns show up.
Geo-spoofing
Licensing is national and regulated operators must not take bets from where they are not permitted. Players and operators of feeder networks use VPNs and proxies to appear somewhere else, and abroad-based operators of account networks need to look Brazilian. Our guide to geo-spoofing and license compliance goes into the regulatory side.
The device layer
The control that cuts across all four patterns is device identity. On the website, Prynt’s JavaScript agent produces a stable visitorId that survives cleared cookies and incognito windows; in the app, the mobile SDKs do the same and add mobile-integrity signals. On your server, the event for each requestId includes:
accountsOnDevice: every player account you have linked to this device;- multi-account and account-sharing signals (
MULTI_ACCOUNT,ACCOUNT_SHARING), andDEVICE_SPREADwhen one account appears on many devices; - mobile integrity: emulator, cloned app (
CLONED_APP), rooted or jailbroken (ROOTED_OR_JAILBROKEN), instrumentation (INSTRUMENTATION), failed attestation (FAILED_ATTESTATION); - network:
VPN,PROXY,RESIDENTIAL_PROXY,TOR,DATACENTER, andLOCATION_SPOOFINGwhen timezone, locale and IP country disagree.
The key step is linking. After registration, attach the player id:
// after the player passes KYC and the account is created
await prynt.updateEvent(requestId, { linkedId: String(player.id) }); // @prynt/node
From then on, every identification on that device knows which player accounts have been there before.
Where to put the checks
Registration. Before you spend money on facial recognition, check the device. A device that already holds several player accounts, or an emulator, is a reason to review before KYC runs, not after.
const ev = await prynt.getEvent(requestId);
const others = ev.accountsOnDevice?.count ?? 0;
if (ev.decision === 'block' || others >= 1) {
return sendToManualReview(ev.risk?.reasons);
}
A limit of one other account is strict and appropriate for betting, where one account per person is the rule. Expect legitimate exceptions, such as a couple sharing a tablet, and route them to review rather than refusing outright.
Login and new devices. Feeder accounts change hands. When an account that has always logged in from one phone suddenly logs in from an emulator that also holds four other accounts, that is the handover.
Withdrawals. Payouts go to an account in the player’s name, which helps, but feeders pass the money on. A withdrawal requested from a device linked to many accounts deserves a hold.
Promotion redemption. Check accounts-per-device before granting any per-account benefit.
Connecting the accounts
Single-device links are the start. Feeder networks show up as clusters: devices sharing accounts, accounts moving between devices, the same IP ranges and hardware profiles. The fraud rings page describes how those links are surfaced, and the igaming solutions page covers the wider set of controls for operators.
Keep a record
Regulated operators need to show their work. Store, for each decision, the visitorId, the accounts on the device at that moment, and the reason codes. When a player disputes a held withdrawal or a regulator asks how you enforce one account per person, you can point at specific evidence rather than a score.
Strong KYC tells you each person is real. Device intelligence tells you how many of those real people are being operated from the same place. In Brazil’s market you need both, and the second is often the one still being built. Start by linking accounts at registration and running a report of devices with more than one player; the bonus abuse guide covers what to do with the first list.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.