[Carding Mastery β€” Case Studies] 5 Real Operations from BIN Selection to Final Payout (Redacted)

Blacksec

Administrator
Staff member
πŸ“‹ CARDING CASE STUDIES πŸ“‹

5 Real Operations β€’ Redacted but Accurate β€’ From BIN to Clean Cash



⚑ AUTHOR'S NOTE:

These are real operations I ran between 2023 and 2026. Details like card numbers, specific sites, vendor names, and exact locations have been redacted β€” but the amounts, methods, timelines, and decision-making are accurate.

Each case study follows the same format:
  1. BIN / Card type used
  2. Target site and why it was chosen
  3. Setup (proxies, profiles, anti-detect)
  4. The transaction (approvals, declines, surprises)
  5. Cashout method and final return
  6. Lessons learned

Some of these made money. Some were losses. All taught me something.



πŸ“Œ TABLE OF CONTENTS

  • Operation 1: The Shopify Sneaker Flip ($4,200 from 8 Transactions)
  • Operation 2: The Amazon Digital Run ($0 β€” Total Loss, But Valuable)
  • Operation 3: The Travel Card Play ($8,600 in 3 Days)
  • Operation 4: The EU Fashion Carding ($6,300 from EU Boutique)
  • Operation 5: The Merchant Refund Exploit ($12,000 from One Account)



πŸ”΄ OPERATION 1: THE SHOPIFY SNEAKER FLIP

Vibe: Classic card-and-resell. Nothing fancy, executed cleanly.

BIN Used: 414720 (Chase Sapphire Preferred)
Cards Purchased: 12 cards from private vendor @ $25 each = $300
Target: Small boutique Shopify store selling limited-run sneakers

Setup:
  • Multilogin profiles x 4 (rotating between sessions)
  • Residential proxies from BrightData β€” New York metro area (matching card billing)
  • Drop address: freight forwarder in Brooklyn (validated, clean)
  • Liquidator: Pre-arranged buyer on a sneaker forum (85% of retail)

The Run:

[TIME]Day 1 β€” Recon[/TIME]
Code:
12:00 β€” Recon the site. Small Shopify store, maybe 50 products.
12:15 β€” Test checkout flow with a prepaid Visa. No 3DS. No AVS on ZIP only.
12:30 β€” Identify 4 pairs of sneakers with high resale demand ($180-250 each)
12:45 β€” Contact liquidator. He agrees to 85% for DS (deadstock) pairs.
13:00 β€” Done. Total recon time: 1 hour. Ready for tomorrow.

[TIME]Day 2 β€” Execution[/TIME]
Code:
09:00 β€” Load first Multilogin profile (NY proxy, fresh fingerprint)
09:15 β€” Browse site, add first pair to cart
09:20 β€” Checkout with card #1. Enter billing address matching fullz.
09:25 β€” Processing... 30 seconds...
09:26 β€” βœ… APPROVED. Order confirmation received.
09:30 β€” Screenshot confirmation. Email receipt forwarded to drop.
09:35 β€” Close profile. Create new one. Rotate proxy.
10:00 β€” Card #2. Same process. βœ… APPROVED.
10:30 β€” Card #3. βœ… APPROVED.
11:00 β€” Card #4. ❌ DECLINED. (Card #4 was dead β€” vendor replaced it)
11:30 β€” Card #5. βœ… APPROVED.
...
15:00 β€” 8 cards approved out of 12. 66% approval rate.
15:30 β€” Total goods value: $1,720
16:00 β€” 3 pairs already shipped by end of day. 5 more pending.

[TIME]Day 5-14 β€” Shipping & Liquidation[/TIME]
Code:
Day 5: 4 pairs delivered to freight forwarder
Day 6: Forwarder repackages and ships to liquidator (international)
Day 10: Liquidator receives. Confirms condition. Transfers $1,462 to escrow.
Day 12: 3 more pairs delivered. Forwarder ships.
Day 14: Final pair delivered.
Day 16: Liquidator confirms all 8 pairs. Final payout: $3,780.
Total escrow fees: $378 (10%)
Net payout from liquidator: $3,402

Final Breakdown:

Code:
Gross goods value:       $1,720
Cards purchased:         $300 (12 x $25, 4 dead)
Proxies (3 weeks):       $60
Multilogin:              $30 (prorated)
Freight forwarder:       $40 (shipping + handling)
Escrow/liquidator fees:  $378 (10%)
Total cost:              $808

Payout from liquidator:  $3,402
Net profit:              $2,594
ROI:                     321%
ROI minus failed cards:  188%

Time invested:  ~14 hours total
Hourly rate:   $185/hour

πŸ”₯ Lessons Learned:
  • Small Shopify stores are the sweet spot β€” big enough to have inventory, small enough to have weak fraud detection
  • Freight forwarders add 7-10 days but break the chain between you and the liquidator
  • 66% approval rate is solid. 33% dead cards is normal from most vendors β€” factor this into pricing
  • Pre-arranging the liquidator BEFORE you card is critical. Don't card first and look for a buyer later
  • Sneakers have the best resale consistency. Streetwear fluctuates more.



πŸ”΄ OPERATION 2: THE AMAZON DIGITAL RUN

Vibe: Thought I was smart. Got humbled.

BIN Used: 462222 (Bank of America Cash Rewards)
Cards Purchased: 15 cards @ $18 each = $270
Target: Amazon.com (digital gift cards)

Setup:
  • 5 aged Amazon accounts (6-18 months old, purchased from vendor @ $30 each)
  • Indigo anti-detect browser with fresh profiles per account
  • Residential proxies matching each account's registered region
  • Amazon gift card balance loaded via legitimate reloads on each account (small amounts)

The Run:

[TIME]Day 1[/TIME]
Code:
10:00 β€” Load Account 1 (18mo old, CA, 20+ legitimate purchases)
10:15 β€” Attempt to add CC #1. 
        Amazon asks for "Verify payment method" β€” requires OTP.
        ❌ Dead end. Card needs phone verification.
10:30 β€” Account 2 (12mo, TX, 10 purchases)
        Add CC #2. Goes through.
        Buy $200 Amazon gift card. βœ… Instant delivery.
        Try to buy $300 more. ❌ Blocked. "Unusual activity."
11:00 β€” Account 3 (6mo, FL, 5 purchases)
        Add CC #3. Requires OTP. ❌
11:15 β€” Account 4 (8mo, NY, 12 purchases)
        Add CC #4. Goes through.
        Buy $150 gift card. βœ… Delivered.
        Try $200 more. ❌ Blocked.
12:00 β€” Account 5 (24mo, IL, 30+ purchases)
        Add CC #5. Goes through.
        Buy $250 gift card. βœ… Delivered.
        Try $300 more. βœ… Delivered. (Aged account cleared higher limit)
12:30 β€” Total: $900 in Amazon gift cards from 5 cards on 5 accounts.
13:00 β€” Accounts 2, 4, 5 all show "We noticed unusual activity" warnings.
13:30 β€” Try to buy more cards. All accounts locked for review.

[TIME]Days 2-7 β€” Liquidation[/TIME]
Code:
Gift cards total: $900
Sold via Paxful for BTC at 82% rate: $738 BTC
BTC β†’ XMR via ChangeNow: $738 β†’ 0.95 XMR (fee: $5)
XMR wallet hold: 48 hours
XMR β†’ BTC via SideShift: 0.95 XMR β†’ $705 BTC (fee: $8)
BTC β†’ Cash via Bisq: $705 β†’ $684 (fee: $21, bank transfer)

Final clean cash: $684

Final Breakdown:

Code:
Gross value:             $900
Cards purchased:         $270 (15 cards, only 5 worked)
Aged accounts:           $150 (5 x $30)
Proxies:                 $25
Anti-detect:             $20
Total cost:              $515

Clean cash:              $684
Net profit:              $169
ROI:                     32%

Time invested:           ~20 hours (mostly waiting)
Hourly rate:             $8.45/hour

⚠️ What Went Wrong:
  • Amazon has the best fraud detection of any retailer. Their OTP verification blocks most new cards.
  • Only 33% of cards worked (5/15) β€” Amazon's system is aggressive.
  • Account age is critical. Only the 24-month account with 30+ purchases could do multiple transactions.
  • $169 profit for 20 hours of work = minimum wage. This was a failure.
  • Amazon tracks more than just the card β€” they track shipping address patterns, login IPs, and device fingerprints across sessions.

πŸ”₯ Lessons Learned:
  • Don't waste time on Amazon unless you have aged accounts with established purchase history
  • The gift card limit is about $200 per account per day regardless of card limit
  • Amazon will lock accounts and keep the gift card balance if they detect fraud
  • The 32% ROI was barely worth it. Better targets exist.
  • Aged accounts cost $30 but you need 5+ of them to make any real volume
  • This method is dead for high volume. Move on.



πŸ”΄ OPERATION 3: THE TRAVEL CARD PLAY

Vibe: High-end cards, low friction, big returns.

BINs Used: 414720 (Chase Sapphire Preferred), 373451 (Amex Platinum)
Cards Purchased: 6 cards @ $40-60 each = $310
Target: Luxury hotel booking site (small, unbranded, accepting direct CC)

Background:

Found a boutique hotel booking site that didn't use 3DS. They catered to wealthy travelers β€” $500-2000/night rooms. Their fraud detection was basically non-existent. They just wanted bookings.

The Setup:
  • No anti-detect browser needed β€” site didn't fingerprint
  • Residential proxies matching each card's region (4 US, 2 UK)
  • Traveler profile: High-end, no extended stay, no suspicious requests
  • Book rooms 2-3 weeks in advance (less fraud scrutiny)
  • Cancel within 24 hours of check-in (full refund to different account)

The Method:

This wasn't a gift card play. This was a refund exploit.

Code:
Phase 1: Book (Day 1)
  - Book a 3-night stay at $1,200/night = $3,600 total
  - Use Chase Sapphire card ($40 cost)
  - Free cancellation policy within 24h of check-in
  - Card approved. Confirmation received. βœ…

Phase 2: Wait (Day 1-19)
  - Let the booking sit. Don't touch it.
  - The hotel sees a legitimate reservation.
  - No fraud flags because nothing unusual happens.
  - The card posts the transaction (~3-5 days for hotels).

Phase 3: Cancel & Redirect Refund (Day 20)
  - 24 hours before check-in, call the hotel directly
  - "My travel plans changed. I need to cancel and get a refund."
  - Hotel: "Of course. The refund will go back to your card."
  - "Actually, can you refund to a different card? My original card was stolen."
  - Hotel: "We'll need to verify..."
  - If they won't change it β†’ accept the original card refund (card is burned anyway)
  - If they will refund to a different card β†’ give them your drop's prepaid card
  - Either way: the $3,600 is refunded. 
  
  But here's the trick β€” the original card has already been charged. 
  The refund goes back. But YOU already moved the value.
  
  Alternative: Book with Refundable Rate.
  Cancel within window. Refund goes to card. You've already spent the card elsewhere.
  The $3,600 cancellation refund effectively credits the cardholder β€” the cardholder thinks 
  "oh, I got a refund!" and doesn't dispute. No chargeback. Clean.

Results:

Code:
Card 1: Chase Sapphire β€” Booked $3,600 package β†’ Cancelled β†’ Refunded
  Net: Cardholder sees refund, doesn't dispute. $3,600 in usable bookings confirmed.
  
Card 2: Chase Sapphire β€” Booked $2,800 β†’ Cancelled β†’ Refunded
  Same play. Clean.
  
Card 3: Amex Platinum β€” Booked $4,200 β†’ Amex declined original auth after 3 days
  ❌ Amex caught it. Chargeback initiated. Site banned the booking.
  Loss: $60 card cost. No goods received on our end.
  
Card 4: Chase Sapphire β€” Booked $1,800 β†’ Used non-refundable rate (by mistake)
  ❌ Couldn't cancel. Loss of $40 card cost. Hotel kept the booking.
  
Card 5: Chase Sapphire β€” Booked $3,200 β†’ Cancelled β†’ Refunded βœ…
Card 6: Amex Platinum β€” $2,600 β†’ Cancelled β†’ Hotel refunded to different card βœ…

Total bookings made: $18,200
Total cashout from clean plays: $12,400
Total costs: $310 (cards) + $0 (no goods to liquidate)
Net profit: $12,090

The Critical Insight:

The refund exploit works because:
  1. Hotels are used to cancellations β€” it's a normal part of their business
  2. Luxury hotels have lenient cancellation policies (they compete on service)
  3. The chargeback window (120 days for Amex, 90 for Visa) is longer than the booking window
  4. By the time the legitimate cardholder notices, the booking has come and gone
  5. Refunding to a different card isn't standard but can be social-engineered

⚠️ Risk: The Amex chargeback (Card 3) flagged that card. The site may have blacklisted the BIN. But with 4 successful plays out of 6, the ROI was absurd.



πŸ”΄ OPERATION 4: THE EU FASHION CARDING

Vibe: EU-based. Cross-border. Higher difficulty but higher fashion resale value.

BIN Used: 491700 (Barclays UK Platinum), 556731 (Capital One β€” worked in EU surprisingly)
Cards Purchased: 10 cards @ Β£25-35 each = Β£300
Target: Italian luxury fashion boutique (medium-sized, ships EU-wide)
Region: UK-based carder targeting an Italian merchant. This means cross-border complexity.

The Challenge:

  • EU merchants have stricter 3DS enforcement (PSD2 regulations)
  • Italian merchants are more suspicious of UK billing addresses post-Brexit
  • Shipping within EU is easier than US β†’ EU
  • However, EU merchants often don't check AVS as strictly as US merchants

Setup:
  • Anti-detect: Multilogin with EU-based profiles
  • Proxies: Residential UK proxies for UK cards, EU proxies for any US cards used
  • Shipping: DPD drop point in Italy (parcel pickup, no ID required)
  • Resale: Italian luxury goods have 80-90% resale value in EU markets

The Run:

Code:
Day 1:
14:00 β€” Browse the site. High-end Italian fashion: bags ($800-2000), shoes ($400-800), belts ($200-500).
14:30 β€” Add a Gucci bag (€1,200) to cart.
14:45 β€” Checkout with Barclays UK card. Billing address = UK fullz. Shipping = Italian drop point.
14:46 β€” ❌ 3DS verification required. "Your bank needs to verify this transaction."
14:50 β€” No access to cardholder phone. Card dead for this use.

Day 2: Strategy Change
10:00 β€” Test same site with Capital One US card.
10:05 β€” No 3DS. Goes straight to authorization.
10:06 β€” ❌ "This transaction cannot be processed." 
        (US card on EU merchant, maybe currency conversion blocked)
10:30 β€” Research: need an EU-issued card for EU merchants. 
        US cards rarely work on high-value EU fashion sites.

Day 3: New BINs
14:00 β€” Tried with Barclays card again, but on a DIFFERENT EU fashion site.
14:02 β€” No 3DS (this site didn't check!). βœ… Addressed matched.
14:05 β€” βœ… APPROVED. €890 leather jacket.
14:30 β€” Same site, different Barclays card. βœ… APPROVED. €650 boots.
15:00 β€” Third card. βœ… APPROVED. €420 belt.
15:30 β€” Fourth card. βœ… APPROVED. €1,100 handbag.
16:00 β€” Total: €3,060 in luxury goods.

Day 5-14: Shipping
  - All shipped to DPD drop point in Milan.
  - Picked up by local contact (paid €200, ~8% of goods value).
  - Contact resold through Vestiaire Collective and local market.
  - Net return: ~75% of retail = €2,295.
  - Contact took 20% = €459.
  - Final to me: €1,836.

Total costs: Β£300 (cards) + €200 (local pick-up) = ~€550
Net profit: €1,836 - €550 = €1,286

Final Breakdown:

Code:
Cards purchased:  10 cards @ ~Β£30 = Β£300
Working cards:    4 (40% approval β€” EU is brutal)
Goods value:      €3,060
Liquidated:       €1,836 (60% after losses + local contact fee)
Total costs:      ~€550
Net profit:       €1,286
ROI:              134%

Time invested:    ~25 hours
Hourly rate:      ~€51/hour

πŸ”₯ Lessons Learned:
  • US cards rarely work on EU high-value merchants. Get EU-issued cards for EU targets.
  • 3DS is mandatory on most EU merchants. But some smaller ones haven't implemented it.
  • Test each merchant with a small transaction first (if possible) to see if 3DS is triggered.
  • DPD drop points in Italy don't require ID for pickup. This is a massive opsec win.
  • Luxury fashion resale in EU is 70-85% vs 60-75% in US (higher demand for European brands).
  • Local contacts take 15-25% but are worth it β€” shipping internationally with customs is a pain.
  • EU carding is harder than US but the margins are better when it works.



πŸ”΄ OPERATION 5: THE MERCHANT REFUND EXPLOIT

Vibe: Big brain. High risk. Maximum reward.

BIN Used: N/A β€” this wasn't carding consumers. This was compromising a merchant.
Investment: $1,200 (for tools, recon, and initial social engineering setup)
Target: Medium-sized e-commerce store (Shopify) doing ~$50k/month in revenue

The Method (Step by Step):

  1. Identify a Shopify store with high transaction volume (gift shop, home goods)
  2. Check the store's Shopify admin URL β€” many store owners don't change the default /admin path
  3. Social engineer the store owner's credentials
  4. Log into Shopify admin
  5. Navigate to Orders β†’ find a high-value order from 60+ days ago (past chargeback window)
  6. Process a "refund" to the original card (which has probably been cancelled by now)
  7. When the refund fails β†’ Shopify gives you options: issue store credit or refund to a different card
  8. Enter your prepaid card or drop card details
  9. Money hits your card within 3-5 business days
  10. Withdraw from ATM and convert to crypto

The Social Engineering:

Code:
Target: Owner of a home goods store in Portland, OR

Step 1: Information gathering
  - Found owner's work email via LinkedIn: [redacted]@storename.com
  - Found Shopify store domain: storename.myshopify.com
  - Found owner's personal Instagram (lots of travel posts β€” good for social engineering timing)

Step 2: Phishing approach
  - Sent email as "Shopify Security Team" β€” professional, no red flags
  - "We've detected unusual login attempts on your admin account"
  - "Please verify your account to prevent suspension"
  - Link redirects to convincing Shopify login clone (hosted on compromised VPS)

Step 3: Credentials captured
  - Email: [redacted]@storename.com
  - Password: [redacted]
  - 2FA: Owner didn't have 2FA enabled (common mistake)

Step 4: Access granted
  - Logged into Shopify admin
  - Full access: orders, customers, payments, settings

The Execution:

Code:
Once inside the Shopify admin:

Phase 1: Recon (Day 1)
  - Reviewed order history. Found 200+ orders in the last 90 days.
  - Identified 12 orders over $500 that were 60+ days old (past chargeback window).
  - Total potential: ~$15,000 in refundable orders.

Phase 2: Testing (Day 1-2)
  - Refunded Order #4821: $620. Refund went to original card (disposable).
  - Waited 24 hours. No chargeback. No email from owner. No response.
  - Test passed β€” the owner wasn't monitoring refund activity.

Phase 3: The Main Event (Day 3)
  - Refunded 4 orders: $840, $720, $1,200, $660 = $3,420 total.
  - All refunds to the original cards (all probably cancelled by now).
  - Refunds failed (as expected). Contacted Shopify support as "store owner."
  - "Three of my customers' refunds failed. Can I reissue to different cards?"
  - Shopify support: "Sure, just provide the new card details."
  - Provided drop card details for all 4 refunds.
  - Within 48 hours: $3,420 posted to drop card.

Phase 4: Scale (Day 5)
  - Repeated with 6 more orders: $5,800 total.
  - Same play. $5,800 to drop card.
  - Total from this merchant: $9,220 before accounts were locked.

Phase 5: Exit (Day 7)
  - Owner noticed when a customer asked about their order status 
    (the refund had cancelled their original order).
  - Owner changed password. Enabled 2FA. Contacted Shopify.
  - Too late. Already pulled $9,220.
  - Total time from first access to exit: 7 days.

Final Breakdown:

Code:
Total refunded:          $9,220
Investment:             $1,200 (VPS, phishing domain, drop cards, proxy)
Net profit:             $8,020
Time invested:          ~12 hours active
Hourly rate:            $668/hour

Risk factors:
  - Shopify might report to law enforcement
  - The phishing domain could be traced (if not properly anonymized)
  - The owner might dispute with their payment processor
  - Long-term legal risk: higher than regular carding

πŸ”₯ Lessons Learned:
  • Merchant-level exploitation pays 10x more than consumer carding for 1/10 of the effort
  • Average Shopify store owners have terrible security β€” no 2FA, weak passwords, no monitoring
  • Shopify support will happily help you refund to different cards if you sound like a legitimate store owner
  • The 60-day chargeback window is your friend β€” refund orders past this window
  • Never refund more than $10k from a single merchant β€” smaller amounts fly under the radar
  • This method works on WooCommerce stores too (different admin panel, same principle)
  • The biggest risk isn't technical β€” it's that the store owner notices and reacts quickly

⚠️ This method carries higher legal risk than standard carding. You're directly defrauding a business rather than using stolen cards. If caught, the charges are more severe. Only use this if you understand the risk profile.



πŸ“Š AGGREGATE STATISTICS

Code:
Total Investment (all 5 ops):   $3,035
Total Return (all 5 ops):        $24,993
Net Profit:                      $21,958
Average ROI:                     724%
Average Hourly Rate:             $309/hour
Success Rate:                    4/5 operations profitable

OperationInvestmentReturnROIHourly
Shopify Sneaker Flip$808$3,402321%$185/h
Amazon Digital Run$515$68432%$8/h ❌
Travel Card Play$310$12,0903,800%$672/h
EU Fashion Carding~€550€1,836134%€51/h
Merchant Refund Exploit$1,200$9,220668%$668/h



END OF CASE STUDIES

Every operation taught me something. Even the losses. Especially the losses.
The goal isn't to avoid failure β€” it's to have failures small enough that you survive to try again.
 
Top