All articles Industry

Crypto Exchange Signup Bonuses: Farming and Rented KYC Accounts

Exchange signup bonuses are an acquisition tool: deposit a set amount, trade a set volume, collect a reward in crypto or fee credits. Referral programs add a second reward for the person who brought the user in. Paid out in a liquid asset, these bonuses are among the most directly cash-out-able promos online. That’s why bonus farming at exchanges is organized, patient and good at getting through KYC.

The farming playbook

Exchange farming differs from ordinary trial abuse in one important way: KYC. You can’t open an account with a throwaway email. You need a real person, a real document and a real selfie. Farmers adapt in three ways.

Rented and bought verified accounts

The most common approach skips faking KYC altogether. People are paid to complete verification with their own identity and then hand over the credentials. Sometimes they sell a whole pre-verified account. Every check passes, because a real, consenting person did each step.

Device farms and emulators

The operator then runs many such accounts from a small set of devices: rows of phones, emulator instances, or browser profiles behind residential proxies. Each account gets its own IP and its own “phone,” at least on the surface.

Referral self-dealing

Farmers chain accounts through each other’s referral codes, so each new rented account pays a referral reward to an account the same operator controls. Referral fraud detection at signup covers that loop in general.

The bonus terms usually require a deposit and some trading volume. Farmers meet them with the minimum deposit, wash-style trades between their own accounts, and a quick withdrawal once the bonus unlocks.

Why KYC alone can’t solve it

KYC answers “is this a real, sanctioned-screened person?” For rented accounts the answer is truthfully yes. KYC isn’t designed to answer the questions that expose the farm:

  • Who is operating this account after verification?
  • How many other accounts does that operator’s device run?
  • Do these accounts’ deposits, trades and withdrawals move together?

Those are device and network questions. Crypto exchange fraud covers the broader threat picture. The rest of this article focuses on the bonus-specific signals.

Signal 1: the post-KYC device switch

A rented account has a telling shape. The account is created and verified on the identity owner’s device, then every later session comes from a different device.

Record the visitorId at each milestone: signup, KYC completion, first deposit, bonus claim, withdrawal. Then compare:

const claim = await prynt.getEvent(claimRequestId);
const kycDevice = await db.milestones.visitorId(account.id, 'kyc_completed');

const deviceSwitchedAfterKyc = kycDevice && kycDevice !== claim.visitorId;
const operatorAccounts = claim.accountsOnDevice.count;   // your accounts seen on the claiming device

if (deviceSwitchedAfterKyc && operatorAccounts >= 2) {
  holdBonus(account.id, 'post_kyc_device_switch_multi_account');
}

A device switch alone is normal. People get new phones, and they use a laptop and a phone. The strong pattern is the combination: a switch soon after KYC to a device that already runs several of your accounts.

Signal 2: accounts per device, over time

Prynt’s risk engine computes several device-level counters you can use directly:

  • multiAccount: two or more distinct accounts (your linkedIds) on one device within 30 days, with the exact number in distinctAccounts30d. Reason code MULTI_ACCOUNT.
  • accountSharing: more than three accounts on one device within 24 hours. Reason code ACCOUNT_SHARING.
  • deviceSpread: one account seen on more than five devices within 24 hours. Reason code DEVICE_SPREAD. That’s typical of credentials passing between workers.

These only work if you attach the account to every identification. Pass linkedId on identification once the user is logged in, or attach it server-side with PUT /v1/events/{requestId} after signup.

In the console rules engine you can turn these into policy without code. For example, distinctAccounts30d gte 3 → challenge on the bonus-claim action, and accountSharing gt 3 (distinct accounts on the device in the last 24 hours) → block. Tag the identification (tag: { action: 'bonus_claim' }) so the rule applies only to that step.

Signal 3: the environment

Farms run on infrastructure that shows up in Smart Signals:

SignalWhy it matters for farms
emulator / virtualMachineMany “phones” on one machine
clonedAppRepackaged or side-loaded app copies, a common way to run several instances on one handset
residentialProxy / datacenterA fresh IP per account to defeat IP clustering
tampering, fridaModified clients to spoof device properties
tlsFingerprintAutomation stacks have different TLS handshakes from real browsers

None of these alone proves farming. Plenty of legitimate traders use VPNs. Together with multi-account counts, they separate a farm from a power user.

Signal 4: network and money flow

Your own data adds the last layer:

  • Withdrawal destination clustering. Many accounts withdrawing to the same external address, or to addresses that consolidate quickly on-chain.
  • Deposit sources. Many accounts funded from one source in a short window.
  • Synchronized trading. Accounts that place the minimum qualifying volume at the same times, often against each other.

Link these with device data in an identity graph, and the components of that graph are the farms. Airdrop farming detection uses the same clustering on the Web3 side.

Where to enforce

  1. At signup: check accountsOnDevice and environment signals. Don’t block a verified-looking user outright, but mark them as not yet bonus-eligible when the device already holds accounts.
  2. At KYC completion: record the device. This is the baseline for the post-KYC switch check.
  3. At bonus credit and at withdrawal: this is where the money moves, so recheck everything. Farmers age accounts to get past signup-time checks. Payout-time checks catch the aged accounts.

Hold rather than confiscate when the evidence is circumstantial, and keep the decision’s reason codes on the case so compliance can explain it later. Label confirmed farms through POST /v1/outcomes. With the opt-in reputation network, a device confirmed as abusive elsewhere can be flagged before it ever claims a bonus from you.

Wrap-up

KYC proves a person exists. It can’t show who operates the account afterwards. Record the device at every milestone, watch for the switch after verification, count accounts per device, and recheck at payout. Farming works at scale only while one operator’s devices can run many verified accounts unnoticed.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading