Serra: The Beast of Small Bites
Card testing attacks start under the radar: tiny repeated transactions, low-value attempts, and rapid retries until a valid payment method is found.
You've captured Serra. Your next trail clue is unlocked at the bottom of this page.
The Serra, or sawfish, hunts prey with small, repeated strikes of its blade-like fin. Card testers bombard your checkout the same way, sending small transactions to test their fraud attempts.
How to prevent Serra's attack
Card testing is how fraudsters validate stolen card numbers. Automated scripts push many small, low-value transactions through your checkout, usually from bots rotating IPs and browser fingerprints, and every approval confirms a live card that can be resold or used for larger fraud. Because each attempt looks like a harmless failed payment, the attack often runs for days before anyone notices.
The damage goes beyond the test transactions themselves: authorization fees per attempt, chargebacks, and a declining approval rate with your payment processor. Defenses that only count requests miss it. Effective prevention looks beyond simple rate limits and inspects browser behavior, automation signals, session patterns, and payment flow anomalies.
Prevention checklist
- Watch failed authorization rates per session, card, and IP. Spikes in low-value declines are the earliest signal.
- Inspect browser behavior and automation signals, not just request counts. Card-testing bots rotate IPs faster than rate limits can follow.
- Detect headless browsers and automation frameworks before traffic reaches the payment step.
- Challenge or throttle suspicious sessions selectively instead of adding friction for every customer.
- Review the scripts running on your checkout. Compromised third-party code can leak card data alongside the testing traffic.
Risk signals and how to respond
Many low-value payment attempts
Repeated failures across cards
Similar browser fingerprints
Sudden checkout spikes
| Risk signal | What it may indicate | Response |
|---|---|---|
| Many low-value payment attempts | Automated card testing | Challenge, block, or throttle suspicious sessions |
| Repeated failures across cards | Credential and payment enumeration | Detect repeated behavioral patterns |
| Similar browser fingerprints | Bot-driven attempts | Use client-side and server-side signals together |
| Sudden checkout spikes | Coordinated abuse | Alert, segment, and review traffic sources |
What it looks like in cside
Automated traffic and session signals
cside surfaces cloud agents, headless browsers, and suspicious sessions: the automated traffic behind card testing.
Checkout script and header monitoring
Continuous monitoring of the scripts and security headers on your payment pages, with weekly change tracking.
Next Trail Clue
The next creature is waiting nearby. Use the clue below to find it, then scan its card to keep going.
Two trees stand together like neighbours. A rock sits at the base of one of them, where your creature is waiting.
Please leave the box exactly where you found it so the next player can find it too. Take one card and put the rest back.