A human doesn’t attempt 50 different credit cards in 10 seconds. Use rate limiting on your payment API. Block any IP or fingerprint that attempts >5 unique cards per minute.

Payment pages should not be stateless. Use a JavaScript attestation challenge on the checkout page. Bots can’t run headless browsers efficiently at high speed.

topics host some of the most updated and professional versions: TeleSentry