All articles Industry

Verified-Fan Registration Abuse: One Fan, Many Entries

Registration-based presales were supposed to fix the ticket rush. Instead of everyone hammering the on-sale page at 10:00, fans register in advance, a draw selects who gets an access code, and selected fans buy in a calmer window. It shifts the fight from speed to identity. And identity, as every scalper has learned, is something you can buy in bulk.

The result is a lottery where one person can hold dozens of tickets in the draw. This post looks at how registration abuse works, why email and phone checks do not stop it, and how to enforce one entry per person with device evidence and a pre-draw audit.

How registration abuse works

A registration lottery has a simple weakness: odds scale with entries. A scalper who submits fifty entries has roughly fifty times the chance of being selected that a fan with one entry has. The tools for producing those entries are well established:

  • Email. Catch-all domains and plus-addressing provide unlimited addresses that all land in one inbox.
  • Phone numbers. Virtual and resold numbers satisfy SMS verification at low cost.
  • Residential proxies. Each registration comes from a different home IP address, often in the right city, so IP-based limits see fifty unrelated households.
  • Automation or cheap labor. Scripts fill registration forms; where scripts are blocked, people paid per registration fill them by hand.
  • Aged accounts. For presales that require an existing ticketing account, scalpers buy or farm accounts months in advance.

Each entry looks individually plausible. The abuse only appears when you look at what entries have in common.

What entries have in common

Scalpers can rotate contact details and IP addresses cheaply. Rotating devices is harder. Running fifty registrations from fifty real phones is expensive, so in practice registrations cluster on a small number of phones, computers, emulators or virtual machines, each with many browser sessions.

That is what device identification exposes. On the registration page, the browser calls identify() and sends the requestId with the entry. On the server you fetch the event and store the device evidence with the entry:

import { PryntServer } from '@prynt/node';
const prynt = new PryntServer({ secretKey: process.env.PRYNT_SECRET_KEY });

const ev = await prynt.getEvent(entry.requestId);
await db.entries.update(entry.id, {
  visitorId: ev.visitorId,
  decision: ev.decision,
  riskScore: ev.riskScore,
  reasons: ev.risk?.reasons ?? [],
  accountsOnDevice: ev.accountsOnDevice?.count ?? 0,
});
// Link only if this identification is not already attached to another fan account:
// overwriting it would erase the evidence of a reused requestId.
if (!ev.linkedId) {
  await prynt.updateEvent(entry.requestId, { linkedId: String(entry.fanAccountId) });
} else if (ev.linkedId !== String(entry.fanAccountId)) {
  await db.entries.update(entry.id, { reusedRequestId: true });
}

The visitorId survives cleared cookies and private windows, so fifty incognito registrations from one laptop share it. Linking each entry’s fan account to the event means every later registration from that device sees how many accounts have already entered from it.

One entry per device

The registration rule follows directly: one entry per device per presale, with a small allowance for genuinely shared devices. A household with one tablet may legitimately register two people; a device with twelve entries is not a household.

You can enforce it at two points:

  • At registration, accept the entry but mark it when the device already holds an entry for this presale. Do not show the fan an error; that only teaches scalpers where your limit sits.
  • At the draw, select at most one entry per device cluster. Duplicates stay in the database and out of the draw.

Catching farms behind residential proxies

Residential proxies defeat IP limits, but they leave other traces. Useful signals for registration traffic:

  • RESIDENTIAL_PROXY: traffic arriving through residential exit nodes;
  • DATACENTER, VPN, TOR: the cheaper anonymization options;
  • LOCATION_SPOOFING: the device’s timezone and locale disagree with the IP’s country;
  • BOT, TLS_AUTOMATION, AUTOMATION_BEHAVIOR: scripted form filling, or a TLS fingerprint that does not match the claimed browser;
  • VIRTUAL_MACHINE and TAMPERING: farms running many browser instances in VMs or with fingerprint-spoofing tools;
  • VELOCITY: many registrations from one device in a short window.

None of these alone proves an entry is fake; plenty of fans use a VPN. Together, and especially when they repeat across a cluster of entries, they describe a farm. The VPN and proxy detection page explains how each network signal is derived.

Audit before the draw

The most effective control is not at the form at all. It is a pre-draw audit, run after registration closes and before anyone is selected:

  1. Group entries by device. Any device with more entries than your household allowance is a cluster.
  2. Group devices by shared evidence. Devices that share accounts, payment instruments, addresses or narrow IP ranges belong to the same operation. The fraud rings page describes how those links form.
  3. Score each cluster. Combine size, automation and anonymization signals, and account age.
  4. Decide per cluster. Keep one entry from a small, clean household cluster; exclude large or automated clusters entirely.
  5. Record the reasons. Store which rule excluded each entry, so support can answer a fan who asks why they were not selected.

Auditing at the end has two advantages. Clusters are only visible once all entries are in, and scalpers get no feedback during registration about which entries were caught.

After the draw

Selected entries become access codes, and codes get resold. Keep the device evidence attached through the sale:

  • Check that the device redeeming a code matches, or is plausibly related to, the device that registered.
  • Watch for one device redeeming codes issued to many accounts.
  • Feed confirmed abuse back as outcomes, so the same devices are recognized at the next presale.

Our posts on presale code abuse and waiting-room and queue abuse cover these later stages, and the ticketing bot prevention guide puts the whole on-sale flow together.

Practical close

You will not make a registration lottery impossible to game. You can make each extra entry cost a real device rather than a free email address, and you can remove duplicates before they win. Start with your next presale: add identification to the registration form, store the device evidence with each entry, and run the device grouping before the draw. The size of the largest cluster will tell you how much of last year’s lottery was decided by scalpers.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading