Glossary

What is bonus abuse?

Bonus abuse is the exploitation of promotional offers, such as signup bonuses, deposit matches, free bets, and referral rewards, by claiming them more times or in ways the terms don't allow. It almost always involves multi-accounting: one person or crew operating many accounts to collect an incentive that was priced for one new customer. The practice is best known in igaming and sports betting, where it is often called bonus hunting, but fintech and trading apps with cash incentives see the same behavior.

How it works

A signup or deposit bonus is a customer acquisition cost. The operator expects to pay it once per real new customer and earn it back over the account's lifetime. Bonus abusers break that math by collecting the bonus many times and contributing nothing afterward.

In igaming, the classic play is bonus hunting across accounts. The abuser registers repeatedly with different emails and identities, deposits the minimum that triggers the match, then clears the wagering requirement with low-risk play: low house edge games, minimum-stake grinding, or hedged bets placed across accounts or competing books so the outcomes offset. Whatever survives the playthrough is withdrawn, and the account goes quiet.

In fintech, the target is usually the deposit or referral incentive. Self-referral is the simplest loop: the abuser creates fake accounts, "refers" them from the main account, cycles the same deposit money through each one, and collects both sides of the reward. At scale this becomes referral farming, with scripted signups, rented identities, and phone farms producing accounts that exist only to trigger a payout.

The abuse isn't always solo. Organized crews run hundreds of accounts using emulators, anti-detect browsers, SIM banks, and purchased identity data. The same infrastructure behind industrial fake account creation powers industrial bonus farming, which is why detection looks similar for both.

How to detect it

Each individual signup looks clean. The signal is in the links between accounts and in the timing.

Device and browser linking is the strongest lever. Device fingerprinting ties "different" customers back to the same hardware: ten accounts claiming a signup bonus from one device is not ten customers. Emulators, anti-detect browsers, and automation frameworks leave their own detectable traces.

Payment linking catches what device signals miss. The same card (BIN plus last four), bank account, or crypto withdrawal address appearing across accounts collapses them into one actor. Watch for deposits that sit exactly at the bonus minimum, and for withdrawals that follow the wagering requirement being cleared by hours.

Identity signals fill in the rest: disposable or aliased email addresses (plus addressing, sequential patterns like name1 and name2), VoIP or freshly issued phone numbers, reused or lightly edited KYC details, and mailing addresses that repeat with trivial variations.

Velocity and graph structure expose the farms. Bursts of signups from one subnet or device in a short window, referral chains that loop back to their origin, and cohorts of accounts created around a promo launch that go dormant when it ends are all strong indicators. A referral graph where reward flows converge on a few cash-out accounts is a farm, whatever each account looks like on its own.

How Rupt handles it

Rupt links accounts by device, network, and behavioral signals at signup and at reward-triggering events, so a bonus claim from a device already tied to previous claimants can be flagged or challenged before payout. The incentive abuse prevention guide walks through the setup, and referral fraud covers the self-referral and referral farming side specifically.