Home / Use case/

Scalping Protection

Back

Stop scalper bots from buying out your drops

Scalper bots and sneaker bots automate the buying journey. They monitor stock, create or reuse accounts, enter queues, add limited products and complete checkout at a scale ordinary customers cannot match.

ADPAL filters automated buying activity before high-confidence bot traffic completes the protected purchase flow. Genuine buyers keep the normal journey, while queues, purchase limits, payment checks and order-review controls stay in place.

.SCALE OF THE PROBLEM

A limited-release problem, not just a sneaker problem

Any scarce product or service can attract scalpers: trainers, consoles, graphics cards, collectibles, event tickets,
hotel rooms, restaurant tables, appointments or seasonal releases. The commercial model is simple: use automation
to acquire limited availability first, then resell it at a markup.

A recognised automated threat

OWASP classifies scalping as OAT-005: acquiring limited-availability or preferred goods and services by methods a normal user could not perform manually.

The operation can scale across identities

Scalping campaigns can coordinate multiple accounts, payment methods and network routes to bypass ordinary purchase limits and appear as separate buyers.

APIs belong in the protection scope

Bots may target stock, account, queue, cart, checkout and mobile API endpoints rather than follow the visible customer journey.

Ticket bots face specific legal restrictions

EU consumer law restricts the resale of event tickets acquired through bots that circumvent purchase limits or other purchasing rules. Ordinary retail-product rules vary by market.

There is no reliable universal scalping percentage. Your own launch, account, order, payment, fulfilment and resale data is the most useful baseline.

.SNIPPET DEFINITION

What are scalper bots and sneaker bots?

The defining point is acquisition. Scalping ends with the product, ticket or booking being secured. Inventory hoarding is different: automation creates a hold without completing the purchase.

Scalper bots are automated buyers that acquire limited products or services faster and at a larger scale than ordinary customers. Sneaker bots are the retail version commonly used for high-demand drops. The automation monitors availability, enters purchase flows and often spreads orders across multiple identities before resale.

.What it looks like

How scalper-bot abuse plays out in a
small store

The example below is illustrative. It explains the pattern without presenting
invented figures as an ADPAL customer case study

The drop goes live. A streetwear label releases 300 pairs at 10:00 after two weeks of promotion. Loyal customers are already waiting on the product page.

The stock disappears immediately. The store appears sold out within minutes. Revenue looks healthy, but many orders show repeated delivery, payment, device or account relationships when the team reviews them.

The resale market moves next. Before lunch, the same product appears on resale platforms at a much higher price. Genuine fans post screenshots and complain that checkout never gave them a realistic chance.

The launch looks better than it was. The stock sold, but the campaign reached resellers first. Demand data is distorted, support work rises and genuine customers learn that joining the next release may not be worth the effort.

A sell-out can therefore be commercially weaker than it looks. Revenue matters, but buyer distribution, repeat participation,
fairness and brand trust matter too.

. Symptoms

Signs scalper bots are hitting your store

A fast sell-out is not proof by itself. Start with business patterns, then confirm them across stock, accounts, orders, payments, edge logs and resale activity.

A release sells out in seconds or minutes despite similar traffic not selling out earlier drops.

Large groups of orders share delivery addresses, phone numbers, card tokens, device traits or account relationships.

Many accounts are created shortly before the release and buy the same SKU immediately.

Sessions reach cart or checkout without a normal product-discovery journey.

Checkout timing is unusually uniform across supposedly unrelated buyers.

Requests rise before launch as automation polls product, stock or API endpoints.

Quantity limits are repeatedly reached through new accounts, identities or payment methods.

The product appears on resale platforms shortly after release and in unusually large quantities.

Support and social channels fill with sold-out-before-checkout complaints from genuine buyers.

Returns, cancellations or payment disputes rise when resale prices fail to meet expectations.

Mobile-app or checkout API activity shows patterns not visible in page-based analytics.

The next release attracts weaker repeat participation despite similar audience reach.

Recognise several signs? It is worth checking

The key pattern

Limited stock disappears quickly, but purchases cluster around coordinated buyer relationships rather than independent customers. One fast checkout is normal. Repeated acquisition across linked buyers deserves investigation.

.Business impact

What scalping actually costs you

The difficult part is that the immediate sales report can look excellent. Stock moved and payment cleared. The commercial
damage appears in who bought, what happened afterwards and whether genuine customers return.

Loyal customers lose access

Fans who planned around the release are beaten by automation. Some pay a reseller; others stop trying and disengage from future launches.

Resellers capture the premium

Your product, marketing and scarcity create the resale margin, but the extra value leaves the brand that invested in demand.

Demand data becomes unreliable

A bot-driven sell-out measures automation capacity as well as genuine demand. Reorder, production and campaign decisions can then use the wrong signal.

Support and community costs rise

Teams handle complaints, duplicate-order reviews, cancellations and questions from customers who never had a realistic chance to buy.

Returns and payment risk increase

Resellers may cancel, return stock or dispute payments when secondary-market prices fall, creating fees and operational work.

Brand trust weakens

Repeated unfair drops turn the story from worth buying into impossible to buy. That can reduce participation in later releases even when every unit technically sold.

For an SMB, measure more than sell-through. Review how much limited stock reached credible individual buyers, how many
orders needed intervention and whether genuine customers returned for the next release.

.How the attack works

How scalper bots beat ordinary
purchase limits

Modern scalping is a workflow rather than one fast script. Different tools can monitor inventory, prepare identities, enter queues,
complete checkout and manage orders while one operator appears as many unrelated buyers.

01

What happens

Monitor the release

Automation polls product pages, stock feeds or APIs and reacts as soon as availability changes.

What you may see

A hidden release time alone does not stop automated monitoring of stock routes.

02

What happens

Prepare buyer identities

Operators create or age accounts and prepare delivery, contact and payment variations before the drop.

What you may see

One-per-account limits are weak when new identities are cheap.

03

What happens

Enter allocation flows

Bots enter waiting rooms, raffles or queues repeatedly and maintain multiple purchase opportunities.

What you may see

Queues control arrival and load, but do not prove one entry equals one buyer.

04

What happens

Automate cart and checkout

Saved profiles, payment tokens and scripted form completion reduce the purchase flow to repeated machine actions.

What you may see

A single checkout can look valid even when many similar buyers are coordinated.

05

What happens

Complete and manage orders

Successful purchases are monitored, adjusted, cancelled or prepared for resale.

What you may see

Post-order relationships and fulfilment review remain important after the traffic layer.

Common patterns that support scalping at scale

Account farms

Many prepared profiles bypass per-account purchase limits.

Network rotation

Residential and mobile routes make one operator appear as many independent buyers.

Queue and raffle entry

Automation scales allocation attempts even when pure checkout speed is removed.

Payment and address variation

Cards, wallets and delivery details are changed or distributed to avoid duplicate-order rules.

Web and API automation

Bots can use the same stock, cart and checkout services as the storefront or mobile app.

Post-purchase coordination

Order status, cancellations and resale operations may continue after payment succeeds.

Scalping vs inventory hoarding

Scalping succeeds when automation acquires the limited product, ticket or booking. Inventory hoarding succeeds when automation keeps availability reserved without paying. The same release can face both problems, but the business signal is different: completed concentrated purchases versus phantom stockouts.
Related use case: Inventory hoarding protection →

.How ADPAL prevents it

How ADPAL filters automated buying before the order is placed

ADPAL evaluates covered buying traffic at the managed perimeter before high-confidence automation completes the protected purchase flow. Advanced detection uses behaviour, browser context, network context, request sequence and endpoint activity instead of relying on one IP address or a single speed threshold.

That wider context matters because scalpers can rotate networks, create fresh accounts and deliberately slow their automation. Individual requests change, but the coordinated buying journey can still differ from independent customer behaviour.

Keep queues, purchase limits, payment checks, fulfilment controls and manual order review. Those layers help with coordinated buyers that reach later stages or abuse the business rules after checkout.

No detection system should promise perfect separation. Monitoring, allowlists, release-specific tuning and comparison with genuine order outcomes remain part of a responsible rollout.

01

Review how requests reach and use product, account, queue, cart and checkout routes.

02

Evaluate behaviour, browser context, network context, request sequence and endpoint activity together.

03

Connect repeated buying behaviour across covered routes without trusting one source address or account.

04

Use stronger controls around selected products, categories, endpoints or release windows when risk is highest.

05

Block or limit high-confidence malicious automation. Most genuine users continue normally; Adaptive CAPTCHA appears only in rare, uncertain cases.

. DIY vs. perimeter

What you can do yourself – and
where each measure stops

Measure

Helps?

The practical limit

Queue or waiting room

Partly

Controls bursts and gives buyers an ordered path. Bots can still hold many positions unless entry and identity are protected.

Raffle or ballot

Partly

Removes the pure checkout-speed race. Account farms can mass-enter and reduce a genuine buyer’s odds.

One-per-account limit

Partly

Stops simple repeat buying from one profile. Fresh accounts can bypass the rule.

Address, card or phone limits

Partly

Find obvious duplicate orders. Operators can vary details, use virtual cards or distribute delivery locations.

CAPTCHA or step-up challenge

Partly

Raises the cost of basic automation. Blanket challenges add checkout friction and do not prove one person controls one account.

Invite codes or loyalty access

Partly

Rewards an existing community. Codes can be shared or farmed, while genuine new customers may be excluded.

Manual order cancellation

After the fact

Recovers some stock after reviewers identify abuse. It creates refund work and cannot restore the original buying moment.

Release-time secrecy

Limited

May reduce casual monitoring, but stock endpoints can still be watched and secrecy weakens campaign marketing.

WAF or basic rate limiting

Limited

Useful for exploits and obvious floods. Valid purchases spread across many identities can remain below simple thresholds.

Perimeter bot filtering

Strong layer

Evaluates the automated journey before the transaction completes. It still works best with purchase, payment and post-order controls.

Actionable first step today

Review the previous drop by buyer relationships, not one magic speed threshold. Compare accounts, devices, payments, delivery details, timing and order outcomes. A fast checkout can be a returning customer; a coordinated cluster across many supposedly unrelated buyers is stronger evidence.

Compare the challenge model

Built for small teams

Built for high-demand releases without an
enterprise security team

Explore ADPAL Bot Protection 

Drop-specific protection

Apply stronger policy to selected products, categories, release windows or high-risk transaction routes.

Web and API coverage

Protect covered storefront, stock, cart and checkout endpoints used by browser and mobile journeys. Confirm exact routing during onboarding.

Advanced detection

Evaluate behaviour, browser context, network context, request sequence and endpoint activity rather than trusting one IP decision.

Risk-based handling

High-confidence automation can be blocked or limited. Adaptive CAPTCHA appears only in rare, uncertain cases.

Rules and allowlists

Keep approved crawlers, integrations and internal services available through defined policy.

Works with existing controls

Keep queues, quantity limits, payment checks, fulfilment rules and manual order review as layered controls.

Privacy-conscious operation

Cookieless, no cross-site tracking profiles, EU (Frankfurt) data residency.

Managed deployment

Point your DNS at the managed reverse proxy – live in hours, then a short monitoring period before enforcing. CMS-integrated deployment is available through hosting partners.

ADPAL Bot Protection adds one managed control layer around covered storefront and transaction routes. The goal is practical: protect scarce stock during important releases without putting a new obstacle in front of every genuine buyer. See the broader storefront protection model →

Evidence that belongs
on this page

.Learn more

Learn more about scalper bots and fair product drops

Guide

How scalper bots work – and how to stop them

Guide

How bad bots ruin business logic

Guide

Bot mitigation strategies that actually work

.FAQ

Questions about scalping bot protection

What is a scalper bot?

A scalper bot is software that automates the acquisition of limited products or services. It can monitor availability, enter queues, manage accounts, add items and complete checkout at a scale ordinary buyers cannot match. The stock is often resold at a higher price.

Are sneaker bots different from scalper bots?

Sneaker bot is a common retail name for a scalper bot used on limited footwear and streetwear drops. The same automation model can target consoles, graphics cards, collectibles, tickets, bookings and other scarce releases.

What is the difference between scalping and inventory hoarding?

Scalping ends with acquisition: the bot buys the item, ticket or service. Inventory hoarding ends with a hold: automation reserves availability but does not complete payment. One creates concentrated purchases and resale stock; the other creates phantom unavailability.

Is a fast sell-out proof that bots were involved?

No. Genuine demand can sell out a small release quickly. Look for supporting evidence such as coordinated account, device and payment relationships, unusual API activity, uniform purchase sequences, limit evasion and resale listings. One timestamp is a clue, not a verdict.

Can a queue or raffle stop scalper bots?

Queues and raffles are useful allocation and load-management tools. They remove some speed advantage, but they do not prove that every entry represents one independent buyer. Keep identity rules, purchase limits, bot filtering and post-order review.

Why do one-per-customer limits keep failing?

The rule depends on how customer is defined. Scalpers can use new accounts, virtual cards, alternative addresses, phone numbers and different network routes. Review coordinated purchase relationships rather than trusting one account field.

Will anti-scalping protection slow checkout for real customers?

The objective is to filter high-risk automation before adding friction to every buyer. Actual user impact depends on routing and policy. Most genuine users should keep the normal journey, while Adaptive CAPTCHA is reserved for rare, uncertain cases.

Can I protect only one product or release window?

Targeted protection is appropriate for limited drops. Policy can focus on selected products, categories, routes or campaign windows when the deployed configuration supports those dimensions. Confirm the exact setup during onboarding.

Do I need to protect mobile apps and APIs too?

Yes. Modern stores often use APIs for stock checks, accounts, carts and payments. A bot can call those services directly or imitate the mobile client, so protection should cover the relevant transaction path rather than only the visible product page.

Can a WAF or CDN rate limit solve scalping?

They remain useful for exploits, floods and obvious anomalies. Scalping can use valid purchase actions spread across many buyers and networks. Bot protection adds behavioural and workflow context that a simple per-IP rule does not provide.

Is scalping illegal?

It depends on the product and jurisdiction. Some markets specifically restrict automated ticket purchasing that bypasses purchase rules. Ordinary retail-product resale is not universally illegal. Businesses still need clear terms and local legal advice where enforcement matters.

What should a small business do before its next drop?

Review the previous release, identify coordinated order relationships, protect stock and checkout routes, define purchase rules, test any queue or raffle and prepare a manual-review path. Put the controls in place before launch rather than after the stock is gone.

Can scalper bots target tickets, bookings and appointments too?

Yes. The same automation model can target any scarce allocation: event tickets, rooms, restaurant tables, appointments or limited services. The exact purchase rules differ, but the pattern is the same – automation tries to secure limited availability at a scale ordinary customers cannot match.

Make your next drop land with real customers

You built the product, the audience and the demand. Do not let automated buyers turn that work into somebody else’s
resale margin or teach genuine customers that joining the next release is pointless.

Protect the transaction path, keep purchase and fulfilment controls in place, and measure which buyers actually received
the scarce stock – not only whether the inventory sold out.

No credit card

Cookieless · no cross-site tracking profiles · EU (Frankfurt) data residency