I’m starting this thread to consolidate what is clearly a systemic issue affecting many Shopify merchants, including Shopify Plus stores, and to move the conversation beyond deflection and into actual mitigation.
Over the past several days, I’ve been doing deep analysis on traffic hitting my Shopify Plus store. The results are not subtle.
Roughly 50% of all sessions over recent days are bot traffic originating from China. Not sporadic. Not spikes. Sustained, automated traffic at scale.
This is not theoretical. It is measurable, repeatable, and materially damaging.
What this traffic looks like in practice
-
Geography and volume
Live analytics show thousands of daily sessions from China. This is traffic we do not market to, do not ship to, and do not have any legitimate customer base in. Many other merchants report the same pattern. -
URL structure strongly indicates scraping
Bots are not just requesting clean product URLs. They are hitting product pages with stacked recommendation parameters that mimic internal Shopify recommendation flows.
Example pattern (real traffic):
/products/[product-handle]?pr_prod_strat=e5_desc&pr_rec_id=XXXX&pr_rec_pid=XXXXXXXXXXXX&pr_ref_pid=XXXXXXXXXXXX&pr_seq=uniform
Humans do not land on product pages this way. These parameters are normally injected by Shopify recommendation logic during in-session navigation. Bots are replaying or permuting these parameters to force distinct URLs, which explodes session counts and corrupts analytics.
- Analytics and marketing damage
This traffic is not just “noise.”
It directly affects:
-
Shopify Analytics (sessions, conversion rate, funnels)
-
Facebook and Google pixels (false page views, polluted audiences)
-
Paid analytics tools like Matomo (which bill based on hits and sessions)
-
Internal monitoring and alerting systems
Filtering bots out of reports after the fact does not solve this. The damage is already done by the time the request hits the store.
- IP evidence
We are seeing traffic from Chinese IP ranges such as 202.46.0.0/16 and similar blocks. These are not isolated IPs. They are ranges associated with data centers and automated activity. Merchants cannot block these at the edge because Shopify controls the CDN, WAF, and routing layer.
This is not an isolated complaint
There are already multiple Shopify Community threads describing the same issue:
-
“Massive visits from Chinese bots… overwhelming multiple Shopify stores”
Massive visits from Chinese bots -
“Shopify must act against the massive wave of Chinese bots destroying merchant data and ad performance”
Shopify must act against the massive wave of Chinese bots destroying merchant data and ad performance
In these threads, merchants consistently report:
-
Unusable analytics
-
Inflated session counts
-
Broken attribution
-
No effective platform-level mitigation
The common response from support is to recommend analytics filters or third-party apps. That does not address the root problem.
Why this is a Shopify platform issue
Merchants do not control:
-
The CDN
-
The WAF
-
IP filtering
-
Country-level blocking
-
Edge-level bot challenges
Only Shopify can mitigate this at the correct layer.
For Shopify Plus merchants in particular, the expectation is not perfection, but active platform-level mitigation when a systemic issue is clearly impacting merchant operations.
This traffic is being served HTML. It is executing pixels. It is triggering paid analytics. That means it is not being meaningfully challenged or blocked at the edge.
Public escalation
I have escalated this publicly because private support channels continue to frame this as either unavoidable or out of scope.
I have posted detailed threads on X directed to Tobi Lutke, documenting the issue, linking to community threads, and explaining the technical impact:
These are long, technical threads intended to marshal the right internal attention, not to sensationalize the issue.
Historically, when platform-level problems stall in support, this has been the only reliable way to get infrastructure and network teams involved.
What merchants are asking for
This is not a request for perfection or total bot elimination. It is a request for basic, reasonable platform defenses, such as:
-
Edge-level throttling or challenge rules for known scraping patterns
-
Detection of abusive parameter permutations
-
IP and ASN-based heuristics applied globally
-
Meaningful Plus escalation paths when traffic clearly degrades analytics and paid tooling
Analytics filters are not a solution. Apps that run after HTML is served are not a solution.
Why this matters
For many merchants, analytics integrity is not a “nice to have.” It directly informs ad spend, inventory planning, conversion optimization, and forecasting.
When half of traffic is fake, every downstream decision becomes unreliable.
This is already costing merchants real money.
Closing
I’m adding this post to centralize discussion and evidence so that Shopify cannot treat this as isolated merchant frustration.
If you are seeing similar patterns, please add:
-
Approximate percentage of bot traffic
-
Regions involved
-
Impacted tools (Shopify Analytics, Meta, Google, Matomo, etc.)
-
Whether you are on Plus
This needs to be addressed at the platform level.

