We run a Shopify Plus store on Shopify Payments, and a card-testing bot has been hitting our checkout since June. It escalated hard this month. We went from about 130 abandoned checkouts in all of August to more than 11,000 since September 1st, peaking near 3,800 in a single day. When we pulled a 90-day export, roughly 94% of the abandoned checkouts belonged to the bot.
The pattern, in case it matches yours:
Nearly every checkout uses the same New York ZIP. A handful of phone numbers, most of them in the reserved 555 range, account for almost all of them.
The emails are generated first.last names on gmail, yahoo, outlook and protonmail, and they get reused. Thousands of fake customer records have piled up, and many were auto-subscribed to our marketing list.
Each checkout holds one unit of one cheap product. The bot switches to a different product every few days, so pulling a targeted SKU only moves it to the next one.
It never loads our storefront. Storefront sessions and page views don’t line up with the checkouts, so it’s clearly going straight to checkout through cart links.
Very few checkouts reach payment. Earlier in the year, though, a couple dozen $5 sample orders did get authorized before we caught them. Shopify’s fraud analysis flagged none of the abandoned checkouts.
What we’ve already done or ruled out:
Payment capture is already set to manual.
We already have a Plus support ticket open.
We won’t block by address or require customers to sign in before checkout. Both would turn away real buyers, and our customers won’t tolerate the extra friction.
From reading the other threads, storefront apps, IP and country blockers, and the login captcha can’t touch this, because the bot never loads the pages they run on.
Questions:
Has anyone on Plus stopped this with a cart and checkout validation Function? What did you match on that never caught a real buyer, and did it also cut down the abandoned-checkout records, or only the payment attempts?
For those who had Plus support turn on bot protection: it’s documented as a scheduled event of up to an hour. Did it do anything against continuous traffic like this?
Has Shopify purged fake abandoned checkouts for anyone? There’s no bulk delete in the admin or the API.
Has anyone gotten Shopify Payments to tighten card-testing or velocity controls on their account after documenting an attack?
Has anyone on Plus had Shopify confirm that rate-limiting checkout through their own Cloudflare in front of the domain is a supported setup?
Any experience would help, especially from other Plus merchants.
Two separate problems here and they need different fixes.
The bot traffic itself. reCAPTCHA on checkout plus a bot-protection app that challenges at the cart/checkout step will cut most card-testing. On Plus you also have checkout extensibility, so you can add stricter validation there. 11,000 abandoned checkouts since Sept 1 is large enough that this is organized testing, not casual spam.
Your analytics are now polluted. With ~94% of abandoned checkouts bot-generated, your recovery email metrics and your real drop-off rate are both unreadable. After you put protections in, recheck the failed-payment error rate: declines that were buried under bot noise become visible, and you will see the true rate for real customers.
Quick way to sanity-check the bot share before you touch anything: look at failed payment attempts grouped by session velocity and customer data quality (fake names, same email patterns, impossible addresses). If nearly all declines come from a small set of sessions with nonsense customer data, that is your bot share.
I built Clovia (clovia.app), which does per-session checkout forensics: every failed payment gets its decline reason attached to the session, so bot sessions and real customers separate themselves. Happy to run a free first-pass on your failed payments and show you the split, no install needed.
A checkout validation Function can stop bad attempts before payment, but it wont clear the abandoned checkout junk already created. For rules, dont block just on one ZIP or free email domains; that can hit real buyers. Safer is stacking signals like reserved 555 numbers, crazy session velocity, and obviously generated addresses together.
For the fake abandoned checkouts, Admin/API still have no bulk delete, so ask Plus Support if they can purge or help with reporting. Same ticket: ask about Payments velocity controls after an attack, and whether Cloudflare in front of your domain can rate-limit checkout on Plus (often checkout sits on Shopify’s side, so storefront Cloudflare alone may not cover it). Temporary bot protection helps bursts more than nonstop traffic; CAPTCHA plus validation is the steadier combo.
Abandoned checkouts and actual fraudulent orders that get through. Even though they may stem from the same testing bots, they are very different areas of focus. You need to separate these two very different actions.
Fraudulent orders -
This is the first and foremost issue you should concern yourself with, as it could negatively contribute to bad authorizations and chargebacks. The first thing you should do is create a checkout validation, whether it be through an app like Blockify or whatever, and block checkouts for some metric you deem fit and see if it works. An app built on Shopify’s Cart and Checkout Validation Function API runs server-side on Shopify and can block checkout progression when its rule matches. Do not conflate this with trying to block the bot from reaching the checkout.
Orders that make it through whatever blocks and detection. Manual capture will not change this. The card company already authorized the payment. Manual capture will only change whether or not you capture the authorized funds.
Abandoned Checkouts -
There is currently no way to manually delete an abandoned checkout. They automatically disappear after 3 months. Don’t assume anything, including checkout validation, will solve that clutter. Also to note: Shopify Fraud Analysis does not generate a risk assessment on abandoned checkouts. I repeat: Blocked attempts that never become orders don’t receive an order fraud recommendation.
Abandoned checkouts really only harm 3 areas. Analytics, marketing, and customer profile bloat. There is virtually nothing you can do about the analytics side, apart from creating your own reports. The marketing side, as well as the customer bloat, is downstream, and has its own methods of correction, deletion, and avoiding mass emails from going out.
One more thing worth noting: Shopify explicitly states that attempts it actually identifies as suspected card testing/bot activity shouldn’t appear in the abandoned-checkout list, which makes those 11,000 entries worth escalating.
This is almost exactly the kind of attack that pushed us to build Halt in the first place. We originally built it internally after seeing card-testing traffic hammer large Shopify stores, then eventually turned it into a public app that Shopify just approved a few days ago.
The interesting part here is that your bot is going directly through cart links and rotating products. That’s important because a lot of the usual storefront-level protections won’t ever see it.
Halt works at checkout rather than relying on storefront traffic, IP blocking, or CAPTCHA. We use checkout validation to stop suspicious attempts before they reach payment, while trying to avoid adding friction for legitimate customers.
Your 11,000 abandoned checkouts are an extreme case though, and I’d genuinely be interested in seeing whether the patterns we’re detecting line up with yours. Especially the repeated ZIP, phone numbers, emails, and velocity.
If you’re open to it, give our app a chance and we can improve it based on your needs. This is exactly the kind of real-world card-testing attack we’re trying to understand better as each merchant needs vary.
What app did you end up going with? Ours just got approved by Shopify a few days ago. We want to improve it and release updates constantly to help everyone here.
Agree on challenging at checkout. The second half that bites later is CRM pollution.
If ~94% of abandons are bot, those fake customers and emails will still enter recovery, segments, and lookalike audiences unless you quarantine them. Practical cut from your pattern: same ZIP cluster, 555 phones, recycled first.last emails across major free mail domains.
I would mark those records “bot/card-test,” exclude them from abandon metrics and flows, then keep a short weekly review of new abandon spikes so the next wave does not silently re-enter.
Are recovery emails already going out to that set, or did you pause flows first?
For the pattern you’re describing, I’d separate the problem into two parts: preventing the bot from creating the checkout attempts in the first place, and dealing with the abandoned-checkout records that have already been created.
If the traffic is going directly to checkout/cart links without loading the storefront, I wouldn’t expect a typical storefront bot blocker, country/IP rule, or login CAPTCHA to be very effective. The fact that the bot is rotating SKUs also makes product-specific blocking fairly easy for it to bypass.
For the checkout side, a cart/checkout validation Function may be worth testing if you have a signal that is specific enough not to affect legitimate buyers. I’d be careful about using ZIP, phone prefix, email domain, or a single SKU as the only condition, since each of those can eventually match real customers.
If the main issue is card-testing traffic reaching checkout, there is also a dedicated option for that layer.
Disclosure: I work on Blockio. It is designed to detect and block card-testing bots before they can repeatedly abuse checkout, and it can be started in Monitor mode so you can review the traffic it would block before enabling enforcement: Blockio Card Testing Blocker - Shopify App Store
I’d treat that as complementary to Shopify Plus and Shopify Payments’ own protections rather than a replacement for them. It also won’t necessarily clean up the abandoned-checkout records that were already generated, so I’d still ask Shopify Support specifically what they can do about the historical records and whether they can apply additional controls to the payment/checkout traffic on their side.
Turn off marketing consent capture at checkout so the bot stops growing your list: Settings > Checkout > Marketing options, disable the automatic sign-up and the opt-in checkbox. Then use Flow’s abandoned checkout trigger, if available on your plan, to tag the customer, and exclude that tag from your email segments.
For the abandoned checkout records themselves, there’s still no bulk delete in the admin or API. Ask in your existing Plus ticket whether Support can purge them server-side, and keep the export as evidence for Shopify Payments.
Cloudflare proxying in front of your Shopify domain isn’t something I’d assume is supported; treat that as a question only Plus Support can confirm in writing.
What you are describing is a checkout permalink bot rather than anything on your storefront, which is why the storefront tools did nothing.
On your first question, and this is the part I would want to know before installing anything: a cart and checkout validation function stops the payment attempt, but it will not bring your abandoned checkout count down. The record is created when the bot fills in contact details, and the function runs after that, so the count stays ugly even when every attempt is being blocked. If the 11,000 records are the real cost to you rather than the payment attempts, that is a separate problem, and the lever is Plus support looking at the cart permalink traffic, since that is the door it is walking through.
On what to match on without catching real buyers, your emails are the weakest signal you have. first.last on gmail is also what your actual customers look like, and a disposable domain list will not touch protonmail. The thing that is actually distinctive in what you posted is the same address coming back over and over on single cheap items. Low cart total on its own will block real people, so it only works paired with the repeat.
Worth doing today regardless: turn off the pre-checked marketing consent at checkout so those fake records stop landing in your list, and clear the ones already in there before it costs you sending reputation.
I build an app called Deadbolt that is this exact thing, a checkout validation function with email and cart rules. Run it in test mode for a day first, where it records what it would have blocked without blocking anything, so you can check it against your own traffic before it touches a real buyer. Two things it will not do for you though: it keys on the email address, so the moment your bot rotates to fresh addresses it is through again, and its automatic burst rule counts completed orders, which on traffic like yours that never completes is nothing to count.
Hi there @notavegan
Another Plus strategy is to treat this as checkout abuse, not a traffic problem on your storefront. You can use a Cart and Checkout Validation Function to block things like repeated reserved 555 phone numbers, suspicious ZIP and email combinations, or unusually high rates of checkout activity prior to payment. I would stay away from broad address or SKU rules that may prevent legitimate buyers from purchasng. Additionally, payment authorization controls should be independent of abandoned checkout creation, as preventing card attempts does not necessarily prevent abandoned records from being created. As part of cleanup, you can export the relevant records and then refer to the documentation of the Plus protections available to you to protect against the type of attack you have identified.
The part that interests me here is the downstream effect on recovery data.
If most abandoned checkouts are actually bot-generated, then the recovery numbers become contaminated before the win-back logic even starts.
I’m testing a broader question around lifecycle recovery: how much of the apparent “recoverable revenue” is actually real customer intent?
In your experience running Shopify stores, do you normally separate suspicious checkout activity from genuine abandonment before measuring recovery performance?
Short answer: yes, and the separation has to happen at ingestion, not in the report.
Two things break when bots flood checkout. First, the records themselves: bot sessions create junk customer profiles and abandoned checkouts that pollute segments, flows, and any “recoverable revenue” number. Second, your funnel math: a wave of bot checkouts makes conversion and recovery rates swing for reasons that have nothing to do with real shoppers.
Cleaning that up after the fact with filters and exclusions is fragile, because every new bot pattern needs a new rule. What holds up is discarding bot sessions when the data is collected, so everything downstream (funnels, drop-off points, recovery metrics) only ever sees real shopper traffic.
That is how I built Clovia (clovia.app) to work: bot sessions are filtered at ingestion and discarded, so the checkout diagnostics you see are on real shoppers only. If you install it free (takes 2 minutes), we will personally walk you through your first real results so you can see exactly where genuine abandonment happens.