Stop Multi-Accounting and VPN Abuse on a Rewards Site

Key takeaways

  • No single check stops multi-accounting; combine network, device, payout, and behavior signals.
  • Put the strongest checks at cashout, where abuse turns into real money, not only at sign-up.
  • Prefer soft actions such as holds and reviews for unclear cases, and let a person handle appeals.

How do you stop multi-accounting and VPN abuse?

To stop multi-accounting and VPN abuse on a rewards site, you layer several defenses instead of relying on one: clear rules that allow one account per person, IP checks that flag VPNs, proxies, and data center networks, device signals that link accounts sharing hardware, payout checks that catch several accounts cashing out to the same destination, and holds on new or risky earnings before they can be withdrawn. Each layer catches something the others miss, and together they make abuse slow and unprofitable.

The payoff is real: every abuser you stop before cashout is a reward you keep and a reversal your partners never see. This guide is for owners of rewards websites, GPT sites, and apps with an offerwall. It explains what to check, where to check it, and how to act without punishing honest users. It does not cover how abusers try to get around detection, and it is not legal advice.

Why multi-accounting and VPN abuse cost you twice

When one person runs ten accounts, they collect sign-up bonuses, referral rewards, and offer payouts ten times. When a user in one country hides behind a VPN to look like they are in another, they reach offers that advertisers only pay for in that country. Advertisers and offerwalls find much of this later, and they reverse the results.

By then you have often paid the user. So you lose the reward you paid out, you lose the payout that was reversed, and a rising reversal rate makes your offer partners trust your traffic less. On Sharklio, a reversal reaches your server as a status 2 postback and the payout is deducted from your balance, as explained in Publisher earnings, settlement, and reversals. Proxy traffic and traffic that disguises its real location are prohibited under our traffic quality rules, and most offer partners have similar terms.

What the abuse looks like in your data

  • Account clusters: several accounts created close together from the same device, network, or browser setup, often with similar usernames or email patterns.
  • Shared payout destinations: different accounts that withdraw to the same payment account, wallet address, or gift card email.
  • Location mismatches: an IP address in one country while the device language, time zone, or payment details point to another.
  • Referral loops: a user who invites accounts that never do anything except complete the same bonus steps and pass earnings upward.
  • Machine-like behavior: offers completed faster than a person could, identical sequences of offers across accounts, and activity at the same minutes every day.
  • Emulators and modified apps: mobile traffic that does not come from a genuine device or an unmodified copy of your app.

For the broader picture of bots, click farms, and fake sign-ups, read Ad fraud and bot traffic.

Start with rules you can enforce

Detection only helps if your terms let you act on it. Before you build anything, write down:

  • One account per person, and whether one account per household or device applies.
  • No VPNs, proxies, or other tools that hide a user’s real location while they earn.
  • That you may hold, reverse, or cancel rewards from offers that your partners reverse, and from activity that breaks the rules.
  • How users can appeal, and how long a review takes.

Show the key rules at sign-up and again on the cashout page. Users who know the rules before they earn are less likely to argue later, and honest users appreciate knowing that the site is protected.

Layered defenses for a rewards site or app

1. Sign-up checks

  • Verify email addresses and reject disposable email domains.
  • Use a bot challenge, such as a CAPTCHA or an invisible challenge, on sign-up and login.
  • Rate-limit sign-ups per IP address, per network range, and per device.
  • Hold sign-up and referral bonuses until the new account has done something real, for example completed its first offer and passed its first review.

2. Network and IP intelligence

An IP intelligence service can tell you whether an address belongs to a known VPN, proxy, hosting provider, or data center, and where it is likely located. Check it at sign-up, when a user opens the offerwall, and at every cashout. Compare the IP country with the country on the account, the device language and time zone, and the payout method. A single mismatch can be innocent, but several together deserve a closer look.

3. Device signals

On the web, a device fingerprint combines browser and device characteristics into an identifier that helps you link accounts using the same setup. Treat it as a signal, not proof, because some fingerprints are shared by many identical devices.

In mobile apps, use the platform attestation services. Google’s Play Integrity API helps you check that requests come from your genuine app, installed by Google Play, running on a genuine and certified Android device, and Google recommends verifying the verdict on your server. On iOS, Apple’s App Attest helps your server confirm that a request came from a legitimate instance of your app on a genuine Apple device, and DeviceCheck lets you store two bits per device, which Apple suggests for things like recording whether a device has already claimed a promotion.

4. Account linking

Store the signals you collect with each account and look for overlaps: the same device, the same payout destination, the same network at sign-up, or the same referral chain. The payout destination is often the strongest link, because abusers need to move the money somewhere. Review linked accounts together rather than one at a time.

5. Behavior checks

  • Flag accounts that complete offers faster than a person could.
  • Compare completion patterns across accounts: the same offers, in the same order, on the same days.
  • Watch sudden spikes from one country, device type, or referrer.
  • Track each user’s reversal rate. A user whose results are reversed again and again is either abusing offers or misunderstanding them, and both need attention.

6. Cashout controls

Cashout is where abuse becomes a real cost, so put your strongest checks there:

  • Hold earnings from offers that are often reversed until the reversal risk has passed, and show users the hold.
  • Review first cashouts and large cashouts, by hand or with rules.
  • Require stronger verification above set amounts, such as a phone number or an identity check.
  • Allow one payout destination per account, and flag destinations used by more than one account.

7. Reversal handling

When an offer partner reverses a result, take the matching reward back from the user, once and only for a transaction you credited. Your postback handler should verify every call before it changes a balance; Postback security covers signature checks and duplicate handling, and the Chargebacks docs show what a Sharklio reversal postback looks like.

Signals, what they catch, and how to act

SignalWhat it catchesFalse positive riskSuggested action
VPN, proxy, or data center IPHidden location, scripted trafficMedium: work networks, privacy tools, some mobile carriersBlock earning while connected, ask the user to switch it off
IP country differs from account countryCountry spoofingMedium: travelers, border areasFlag, and review at cashout
Many accounts on one deviceAccount farmsMedium: shared family devicesLink accounts and review together
Same payout destination on several accountsOne person cashing out many accountsLowHold cashouts and review
Failed app attestationEmulators, modified appsLow to medium: old or rooted devicesLimit earning features in the app
Offers completed faster than possibleBots, fake completionsLowHold earnings and review
High personal reversal rateOffer abuse, rule breakingLow to mediumHold new earnings, contact the user

Avoid punishing honest users

Every check can be wrong. Families share a computer, students share a campus network, many mobile users share IP addresses through their carrier, and some people use a VPN for work or privacy without meaning any harm. Blocking all of them loses good users and fills your support queue.

So score rather than guess: combine signals into a risk score and act on the total, not on any one signal. Reach for soft actions first, such as asking the user to turn off a VPN, holding a cashout for review, or asking for verification, before you ban anyone.

Whenever you hold or reverse something, explain the reason in plain words. And offer an appeal that a person reviews. When appeals show a pattern of false positives, fix the rule behind them; that is how your checks get sharper over time.

Privacy and data protection

IP addresses, device identifiers, and fingerprints can be personal data. Collect only what you need for security, keep it only as long as you need it, protect it, and say in your privacy policy that you use these signals to prevent fraud. If you have users in the EU or the UK, data protection law applies to this processing. This is general information, not legal advice, so check the rules that apply to you.

Checklist

  1. Terms say one account per person, no VPNs or proxies, and that reversed rewards are taken back.
  2. Email verification, a bot challenge, and sign-up rate limits are on.
  3. IP intelligence runs at sign-up, wall opening, and cashout.
  4. Device signals are stored, and the mobile app uses Play Integrity or App Attest.
  5. Accounts sharing a device or payout destination are linked and reviewed together.
  6. Risky earnings are held, and first and large cashouts are reviewed.
  7. Reversal postbacks take rewards back once, and each user’s reversal rate is tracked.
  8. Users can appeal, and a person reviews the appeal.

Tracing reversals back to users with Sharklio logs

The Sharklio offerwall has not opened yet, and nobody can sign up for now. Once it does and your app is live, every result on your wall reaches your server through signed postbacks with one transaction ID from pending to credited or reversed, and your dashboard logs show conversions, chargebacks, and postback attempts, so you can see which users and sources cause reversals. Our own checks run on every offer, but the rules on your site are still yours to enforce, so start with the checklist above today. To hear the day it opens, use the email form at the bottom of this page. Meanwhile, see how the Sharklio offerwall works, or read How to start a rewards website for the wider setup.

Frequently asked questions

How do I detect VPN users on my website?

Check each user’s IP address with an IP intelligence service that flags known VPNs, proxies, and data center networks, and compare the IP location with the account country, device language, and time zone. Run the check at sign-up, when the offerwall opens, and at cashout.

Should I block every VPN user?

Block earning while a VPN or proxy is connected, because offers are priced by the user’s real country. You do not need to ban the account for it. Asking the user to turn the VPN off keeps honest users who use one for privacy.

How can I stop one person from creating multiple accounts?

Combine several signals: device identifiers, network at sign-up, payout destination, and behavior. The payout destination is often the strongest link. Hold sign-up and referral bonuses until an account has done real activity, and review linked accounts together.

Is device fingerprinting legal?

It can be used for fraud prevention in many places, but fingerprints can be personal data. Tell users in your privacy policy, collect only what you need, and check the data protection rules that apply to your users.

What happens if multi-accounting reaches my offerwall partners?

They reverse the affected results, so you lose the payout and often the reward you already paid. Repeated abuse can lead to held earnings or a suspended integration, which is why your own checks matter.