5 Real Operations β’ Redacted but Accurate β’ From BIN to Clean Cash
These are real operations I ran between 2023 and 2026. Details like card numbers, specific sites, vendor names, and exact locations have been redacted β but the amounts, methods, timelines, and decision-making are accurate.
Each case study follows the same format:
- BIN / Card type used
- Target site and why it was chosen
- Setup (proxies, profiles, anti-detect)
- The transaction (approvals, declines, surprises)
- Cashout method and final return
- Lessons learned
Some of these made money. Some were losses. All taught me something.
- Operation 1: The Shopify Sneaker Flip ($4,200 from 8 Transactions)
- Operation 2: The Amazon Digital Run ($0 β Total Loss, But Valuable)
- Operation 3: The Travel Card Play ($8,600 in 3 Days)
- Operation 4: The EU Fashion Carding ($6,300 from EU Boutique)
- Operation 5: The Merchant Refund Exploit ($12,000 from One Account)
Vibe: Classic card-and-resell. Nothing fancy, executed cleanly.
BIN Used: 414720 (Chase Sapphire Preferred)
Cards Purchased: 12 cards from private vendor @ $25 each = $300
Target: Small boutique Shopify store selling limited-run sneakers
Setup:
- Multilogin profiles x 4 (rotating between sessions)
- Residential proxies from BrightData β New York metro area (matching card billing)
- Drop address: freight forwarder in Brooklyn (validated, clean)
- Liquidator: Pre-arranged buyer on a sneaker forum (85% of retail)
The Run:
[TIME]Day 1 β Recon[/TIME]
Code:
12:00 β Recon the site. Small Shopify store, maybe 50 products.
12:15 β Test checkout flow with a prepaid Visa. No 3DS. No AVS on ZIP only.
12:30 β Identify 4 pairs of sneakers with high resale demand ($180-250 each)
12:45 β Contact liquidator. He agrees to 85% for DS (deadstock) pairs.
13:00 β Done. Total recon time: 1 hour. Ready for tomorrow.
[TIME]Day 2 β Execution[/TIME]
Code:
09:00 β Load first Multilogin profile (NY proxy, fresh fingerprint)
09:15 β Browse site, add first pair to cart
09:20 β Checkout with card #1. Enter billing address matching fullz.
09:25 β Processing... 30 seconds...
09:26 β β
APPROVED. Order confirmation received.
09:30 β Screenshot confirmation. Email receipt forwarded to drop.
09:35 β Close profile. Create new one. Rotate proxy.
10:00 β Card #2. Same process. β
APPROVED.
10:30 β Card #3. β
APPROVED.
11:00 β Card #4. β DECLINED. (Card #4 was dead β vendor replaced it)
11:30 β Card #5. β
APPROVED.
...
15:00 β 8 cards approved out of 12. 66% approval rate.
15:30 β Total goods value: $1,720
16:00 β 3 pairs already shipped by end of day. 5 more pending.
[TIME]Day 5-14 β Shipping & Liquidation[/TIME]
Code:
Day 5: 4 pairs delivered to freight forwarder
Day 6: Forwarder repackages and ships to liquidator (international)
Day 10: Liquidator receives. Confirms condition. Transfers $1,462 to escrow.
Day 12: 3 more pairs delivered. Forwarder ships.
Day 14: Final pair delivered.
Day 16: Liquidator confirms all 8 pairs. Final payout: $3,780.
Total escrow fees: $378 (10%)
Net payout from liquidator: $3,402
Final Breakdown:
Code:
Gross goods value: $1,720
Cards purchased: $300 (12 x $25, 4 dead)
Proxies (3 weeks): $60
Multilogin: $30 (prorated)
Freight forwarder: $40 (shipping + handling)
Escrow/liquidator fees: $378 (10%)
Total cost: $808
Payout from liquidator: $3,402
Net profit: $2,594
ROI: 321%
ROI minus failed cards: 188%
Time invested: ~14 hours total
Hourly rate: $185/hour
- Small Shopify stores are the sweet spot β big enough to have inventory, small enough to have weak fraud detection
- Freight forwarders add 7-10 days but break the chain between you and the liquidator
- 66% approval rate is solid. 33% dead cards is normal from most vendors β factor this into pricing
- Pre-arranging the liquidator BEFORE you card is critical. Don't card first and look for a buyer later
- Sneakers have the best resale consistency. Streetwear fluctuates more.
Vibe: Thought I was smart. Got humbled.
BIN Used: 462222 (Bank of America Cash Rewards)
Cards Purchased: 15 cards @ $18 each = $270
Target: Amazon.com (digital gift cards)
Setup:
- 5 aged Amazon accounts (6-18 months old, purchased from vendor @ $30 each)
- Indigo anti-detect browser with fresh profiles per account
- Residential proxies matching each account's registered region
- Amazon gift card balance loaded via legitimate reloads on each account (small amounts)
The Run:
[TIME]Day 1[/TIME]
Code:
10:00 β Load Account 1 (18mo old, CA, 20+ legitimate purchases)
10:15 β Attempt to add CC #1.
Amazon asks for "Verify payment method" β requires OTP.
β Dead end. Card needs phone verification.
10:30 β Account 2 (12mo, TX, 10 purchases)
Add CC #2. Goes through.
Buy $200 Amazon gift card. β
Instant delivery.
Try to buy $300 more. β Blocked. "Unusual activity."
11:00 β Account 3 (6mo, FL, 5 purchases)
Add CC #3. Requires OTP. β
11:15 β Account 4 (8mo, NY, 12 purchases)
Add CC #4. Goes through.
Buy $150 gift card. β
Delivered.
Try $200 more. β Blocked.
12:00 β Account 5 (24mo, IL, 30+ purchases)
Add CC #5. Goes through.
Buy $250 gift card. β
Delivered.
Try $300 more. β
Delivered. (Aged account cleared higher limit)
12:30 β Total: $900 in Amazon gift cards from 5 cards on 5 accounts.
13:00 β Accounts 2, 4, 5 all show "We noticed unusual activity" warnings.
13:30 β Try to buy more cards. All accounts locked for review.
[TIME]Days 2-7 β Liquidation[/TIME]
Code:
Gift cards total: $900
Sold via Paxful for BTC at 82% rate: $738 BTC
BTC β XMR via ChangeNow: $738 β 0.95 XMR (fee: $5)
XMR wallet hold: 48 hours
XMR β BTC via SideShift: 0.95 XMR β $705 BTC (fee: $8)
BTC β Cash via Bisq: $705 β $684 (fee: $21, bank transfer)
Final clean cash: $684
Final Breakdown:
Code:
Gross value: $900
Cards purchased: $270 (15 cards, only 5 worked)
Aged accounts: $150 (5 x $30)
Proxies: $25
Anti-detect: $20
Total cost: $515
Clean cash: $684
Net profit: $169
ROI: 32%
Time invested: ~20 hours (mostly waiting)
Hourly rate: $8.45/hour
- Amazon has the best fraud detection of any retailer. Their OTP verification blocks most new cards.
- Only 33% of cards worked (5/15) β Amazon's system is aggressive.
- Account age is critical. Only the 24-month account with 30+ purchases could do multiple transactions.
- $169 profit for 20 hours of work = minimum wage. This was a failure.
- Amazon tracks more than just the card β they track shipping address patterns, login IPs, and device fingerprints across sessions.
- Don't waste time on Amazon unless you have aged accounts with established purchase history
- The gift card limit is about $200 per account per day regardless of card limit
- Amazon will lock accounts and keep the gift card balance if they detect fraud
- The 32% ROI was barely worth it. Better targets exist.
- Aged accounts cost $30 but you need 5+ of them to make any real volume
- This method is dead for high volume. Move on.
Vibe: High-end cards, low friction, big returns.
BINs Used: 414720 (Chase Sapphire Preferred), 373451 (Amex Platinum)
Cards Purchased: 6 cards @ $40-60 each = $310
Target: Luxury hotel booking site (small, unbranded, accepting direct CC)
Background:
Found a boutique hotel booking site that didn't use 3DS. They catered to wealthy travelers β $500-2000/night rooms. Their fraud detection was basically non-existent. They just wanted bookings.
The Setup:
- No anti-detect browser needed β site didn't fingerprint
- Residential proxies matching each card's region (4 US, 2 UK)
- Traveler profile: High-end, no extended stay, no suspicious requests
- Book rooms 2-3 weeks in advance (less fraud scrutiny)
- Cancel within 24 hours of check-in (full refund to different account)
The Method:
This wasn't a gift card play. This was a refund exploit.
Code:
Phase 1: Book (Day 1)
- Book a 3-night stay at $1,200/night = $3,600 total
- Use Chase Sapphire card ($40 cost)
- Free cancellation policy within 24h of check-in
- Card approved. Confirmation received. β
Phase 2: Wait (Day 1-19)
- Let the booking sit. Don't touch it.
- The hotel sees a legitimate reservation.
- No fraud flags because nothing unusual happens.
- The card posts the transaction (~3-5 days for hotels).
Phase 3: Cancel & Redirect Refund (Day 20)
- 24 hours before check-in, call the hotel directly
- "My travel plans changed. I need to cancel and get a refund."
- Hotel: "Of course. The refund will go back to your card."
- "Actually, can you refund to a different card? My original card was stolen."
- Hotel: "We'll need to verify..."
- If they won't change it β accept the original card refund (card is burned anyway)
- If they will refund to a different card β give them your drop's prepaid card
- Either way: the $3,600 is refunded.
But here's the trick β the original card has already been charged.
The refund goes back. But YOU already moved the value.
Alternative: Book with Refundable Rate.
Cancel within window. Refund goes to card. You've already spent the card elsewhere.
The $3,600 cancellation refund effectively credits the cardholder β the cardholder thinks
"oh, I got a refund!" and doesn't dispute. No chargeback. Clean.
Results:
Code:
Card 1: Chase Sapphire β Booked $3,600 package β Cancelled β Refunded
Net: Cardholder sees refund, doesn't dispute. $3,600 in usable bookings confirmed.
Card 2: Chase Sapphire β Booked $2,800 β Cancelled β Refunded
Same play. Clean.
Card 3: Amex Platinum β Booked $4,200 β Amex declined original auth after 3 days
β Amex caught it. Chargeback initiated. Site banned the booking.
Loss: $60 card cost. No goods received on our end.
Card 4: Chase Sapphire β Booked $1,800 β Used non-refundable rate (by mistake)
β Couldn't cancel. Loss of $40 card cost. Hotel kept the booking.
Card 5: Chase Sapphire β Booked $3,200 β Cancelled β Refunded β
Card 6: Amex Platinum β $2,600 β Cancelled β Hotel refunded to different card β
Total bookings made: $18,200
Total cashout from clean plays: $12,400
Total costs: $310 (cards) + $0 (no goods to liquidate)
Net profit: $12,090
The Critical Insight:
The refund exploit works because:
- Hotels are used to cancellations β it's a normal part of their business
- Luxury hotels have lenient cancellation policies (they compete on service)
- The chargeback window (120 days for Amex, 90 for Visa) is longer than the booking window
- By the time the legitimate cardholder notices, the booking has come and gone
- Refunding to a different card isn't standard but can be social-engineered
Vibe: EU-based. Cross-border. Higher difficulty but higher fashion resale value.
BIN Used: 491700 (Barclays UK Platinum), 556731 (Capital One β worked in EU surprisingly)
Cards Purchased: 10 cards @ Β£25-35 each = Β£300
Target: Italian luxury fashion boutique (medium-sized, ships EU-wide)
Region: UK-based carder targeting an Italian merchant. This means cross-border complexity.
The Challenge:
- EU merchants have stricter 3DS enforcement (PSD2 regulations)
- Italian merchants are more suspicious of UK billing addresses post-Brexit
- Shipping within EU is easier than US β EU
- However, EU merchants often don't check AVS as strictly as US merchants
Setup:
- Anti-detect: Multilogin with EU-based profiles
- Proxies: Residential UK proxies for UK cards, EU proxies for any US cards used
- Shipping: DPD drop point in Italy (parcel pickup, no ID required)
- Resale: Italian luxury goods have 80-90% resale value in EU markets
The Run:
Code:
Day 1:
14:00 β Browse the site. High-end Italian fashion: bags ($800-2000), shoes ($400-800), belts ($200-500).
14:30 β Add a Gucci bag (β¬1,200) to cart.
14:45 β Checkout with Barclays UK card. Billing address = UK fullz. Shipping = Italian drop point.
14:46 β β 3DS verification required. "Your bank needs to verify this transaction."
14:50 β No access to cardholder phone. Card dead for this use.
Day 2: Strategy Change
10:00 β Test same site with Capital One US card.
10:05 β No 3DS. Goes straight to authorization.
10:06 β β "This transaction cannot be processed."
(US card on EU merchant, maybe currency conversion blocked)
10:30 β Research: need an EU-issued card for EU merchants.
US cards rarely work on high-value EU fashion sites.
Day 3: New BINs
14:00 β Tried with Barclays card again, but on a DIFFERENT EU fashion site.
14:02 β No 3DS (this site didn't check!). β
Addressed matched.
14:05 β β
APPROVED. β¬890 leather jacket.
14:30 β Same site, different Barclays card. β
APPROVED. β¬650 boots.
15:00 β Third card. β
APPROVED. β¬420 belt.
15:30 β Fourth card. β
APPROVED. β¬1,100 handbag.
16:00 β Total: β¬3,060 in luxury goods.
Day 5-14: Shipping
- All shipped to DPD drop point in Milan.
- Picked up by local contact (paid β¬200, ~8% of goods value).
- Contact resold through Vestiaire Collective and local market.
- Net return: ~75% of retail = β¬2,295.
- Contact took 20% = β¬459.
- Final to me: β¬1,836.
Total costs: Β£300 (cards) + β¬200 (local pick-up) = ~β¬550
Net profit: β¬1,836 - β¬550 = β¬1,286
Final Breakdown:
Code:
Cards purchased: 10 cards @ ~Β£30 = Β£300
Working cards: 4 (40% approval β EU is brutal)
Goods value: β¬3,060
Liquidated: β¬1,836 (60% after losses + local contact fee)
Total costs: ~β¬550
Net profit: β¬1,286
ROI: 134%
Time invested: ~25 hours
Hourly rate: ~β¬51/hour
- US cards rarely work on EU high-value merchants. Get EU-issued cards for EU targets.
- 3DS is mandatory on most EU merchants. But some smaller ones haven't implemented it.
- Test each merchant with a small transaction first (if possible) to see if 3DS is triggered.
- DPD drop points in Italy don't require ID for pickup. This is a massive opsec win.
- Luxury fashion resale in EU is 70-85% vs 60-75% in US (higher demand for European brands).
- Local contacts take 15-25% but are worth it β shipping internationally with customs is a pain.
- EU carding is harder than US but the margins are better when it works.
Vibe: Big brain. High risk. Maximum reward.
BIN Used: N/A β this wasn't carding consumers. This was compromising a merchant.
Investment: $1,200 (for tools, recon, and initial social engineering setup)
Target: Medium-sized e-commerce store (Shopify) doing ~$50k/month in revenue
The Method (Step by Step):
- Identify a Shopify store with high transaction volume (gift shop, home goods)
- Check the store's Shopify admin URL β many store owners don't change the default /admin path
- Social engineer the store owner's credentials
- Log into Shopify admin
- Navigate to Orders β find a high-value order from 60+ days ago (past chargeback window)
- Process a "refund" to the original card (which has probably been cancelled by now)
- When the refund fails β Shopify gives you options: issue store credit or refund to a different card
- Enter your prepaid card or drop card details
- Money hits your card within 3-5 business days
- Withdraw from ATM and convert to crypto
The Social Engineering:
Code:
Target: Owner of a home goods store in Portland, OR
Step 1: Information gathering
- Found owner's work email via LinkedIn: [redacted]@storename.com
- Found Shopify store domain: storename.myshopify.com
- Found owner's personal Instagram (lots of travel posts β good for social engineering timing)
Step 2: Phishing approach
- Sent email as "Shopify Security Team" β professional, no red flags
- "We've detected unusual login attempts on your admin account"
- "Please verify your account to prevent suspension"
- Link redirects to convincing Shopify login clone (hosted on compromised VPS)
Step 3: Credentials captured
- Email: [redacted]@storename.com
- Password: [redacted]
- 2FA: Owner didn't have 2FA enabled (common mistake)
Step 4: Access granted
- Logged into Shopify admin
- Full access: orders, customers, payments, settings
The Execution:
Code:
Once inside the Shopify admin:
Phase 1: Recon (Day 1)
- Reviewed order history. Found 200+ orders in the last 90 days.
- Identified 12 orders over $500 that were 60+ days old (past chargeback window).
- Total potential: ~$15,000 in refundable orders.
Phase 2: Testing (Day 1-2)
- Refunded Order #4821: $620. Refund went to original card (disposable).
- Waited 24 hours. No chargeback. No email from owner. No response.
- Test passed β the owner wasn't monitoring refund activity.
Phase 3: The Main Event (Day 3)
- Refunded 4 orders: $840, $720, $1,200, $660 = $3,420 total.
- All refunds to the original cards (all probably cancelled by now).
- Refunds failed (as expected). Contacted Shopify support as "store owner."
- "Three of my customers' refunds failed. Can I reissue to different cards?"
- Shopify support: "Sure, just provide the new card details."
- Provided drop card details for all 4 refunds.
- Within 48 hours: $3,420 posted to drop card.
Phase 4: Scale (Day 5)
- Repeated with 6 more orders: $5,800 total.
- Same play. $5,800 to drop card.
- Total from this merchant: $9,220 before accounts were locked.
Phase 5: Exit (Day 7)
- Owner noticed when a customer asked about their order status
(the refund had cancelled their original order).
- Owner changed password. Enabled 2FA. Contacted Shopify.
- Too late. Already pulled $9,220.
- Total time from first access to exit: 7 days.
Final Breakdown:
Code:
Total refunded: $9,220
Investment: $1,200 (VPS, phishing domain, drop cards, proxy)
Net profit: $8,020
Time invested: ~12 hours active
Hourly rate: $668/hour
Risk factors:
- Shopify might report to law enforcement
- The phishing domain could be traced (if not properly anonymized)
- The owner might dispute with their payment processor
- Long-term legal risk: higher than regular carding
- Merchant-level exploitation pays 10x more than consumer carding for 1/10 of the effort
- Average Shopify store owners have terrible security β no 2FA, weak passwords, no monitoring
- Shopify support will happily help you refund to different cards if you sound like a legitimate store owner
- The 60-day chargeback window is your friend β refund orders past this window
- Never refund more than $10k from a single merchant β smaller amounts fly under the radar
- This method works on WooCommerce stores too (different admin panel, same principle)
- The biggest risk isn't technical β it's that the store owner notices and reacts quickly
Code:
Total Investment (all 5 ops): $3,035
Total Return (all 5 ops): $24,993
Net Profit: $21,958
Average ROI: 724%
Average Hourly Rate: $309/hour
Success Rate: 4/5 operations profitable
| Operation | Investment | Return | ROI | Hourly |
| Shopify Sneaker Flip | $808 | $3,402 | 321% | $185/h |
| Amazon Digital Run | $515 | $684 | 32% | $8/h |
| Travel Card Play | $310 | $12,090 | 3,800% | $672/h |
| EU Fashion Carding | ~β¬550 | β¬1,836 | 134% | β¬51/h |
| Merchant Refund Exploit | $1,200 | $9,220 | 668% | $668/h |
END OF CASE STUDIES
Every operation taught me something. Even the losses. Especially the losses.
The goal isn't to avoid failure β it's to have failures small enough that you survive to try again.
Every operation taught me something. Even the losses. Especially the losses.
The goal isn't to avoid failure β it's to have failures small enough that you survive to try again.