Slide 15 of 28
Part 3 · Attack ScenariosSlide 15
Slide 15 · Scenario 2
Thousands of fake accounts. Thousands of real payouts.
OWASP Scenario #2 — referral program with no account verification gate.
📄 OWASP API Security Top 10 · 2023 · API6 · Scenario 2
SETUP
A fintech app’s referral program.

A fintech platform offers: refer a friend using your code → they sign up and make a $10 deposit → you receive $20 cash bonus. The API supports account creation with an optional referral code field. Email verification is required — but disposable email services are not blocked.

The exploit: A bot operator writes a script: create account A (uses disposable email, verifies via the disposable inbox API), generate A’s referral code, create account B (another disposable email), sign up B with A’s referral code, fund B with $10 using a prepaid card, trigger referral reward to A. Repeat 1,000 times. Net: operator receives $20,000 in referral bonuses. Platform cost: $20,000 + $10,000 in minimum deposits that are immediately withdrawn. Net loss: $20,000+.
The velocity signal

1,000 referral redemptions in one day from one IP range is detectable. 1,000 referral redemptions spread over a week from residential proxies across 50 countries is much harder to catch. Bot operators optimize for staying below anomaly detection thresholds.

← Back Scenario 3 →