PART 2: THE TRANSACTION
BIN Selection • Site Recon • Anti-Detect Setup • Live Checkout Flow • Troubleshooting
Part 1 covered theory. This is where we get our hands dirty. I'm going to walk you through an actual transaction from start to finish — the exact same process I've used thousands of times.
I'll use a generic US card on a mid-tier Shopify store as the example, but I'll also cover variations for Amazon, digital goods, and EU sites.
Every screenshot, every step, every decision point — it's all here. If you follow this exactly, you will complete your first successful carded purchase. Guaranteed.
- 2.1 — Pre-Flight Checklist (Do NOT Skip This)
- 2.2 — BIN Selection Strategy for Today's Run
- 2.3 — Site Reconnaissance: Finding Cardable Merchants
- 2.4 — Anti-Detect Browser Configuration (Step by Step)
- 2.5 — The Live Checkout Flow (Every Click Documented)
- 2.6 — Handling 3DS Verification
- 2.7 — Post-Purchase: Order Management & Shipping
- 2.8 — Troubleshooting Declines (The Complete Decision Tree)
- 2.9 — Carding Specific Platforms (Amazon, Shopify, Digital Goods, EU)
- 2.10 — Scaling: From Single Transactions to Automated Volume
2.1 — PRE-FLIGHT CHECKLIST
Before you even open a browser, run through this checklist. Missing any single item can tank your entire run.
Code:
[ ] 1. Anti-detect browser profile created with matching fingerprint
[ ] 2. Residential proxy loaded — GeoIP matches cardholder region
[ ] 3. Proxy tested — confirm IP shows correct city via whatismyip
[ ] 4. Card details verified — BIN checked against valid range
[ ] 5. Billing address matches cardholder ZIP code
[ ] 6. Shipping address confirmed (drop or freight forwarder)
[ ] 7. Target site loaded — check if it ships to your region
[ ] 8. Site fraud check — is it known cardable? Recent reports?
[ ] 9. Amount confirmed — under $500 for first test
[ ] 10. Liquidation path ready — buyer waiting or conversion method set
2.2 — BIN SELECTION STRATEGY
For This Session, We're Using:
Code:
BIN: 414720 (Chase Sapphire Preferred)
Type: Visa Credit (Premium)
Expected Approval Rate: 85-92%
3DS Status: Mixed (some are enrolled, some aren't)
Ideal for: US-based Shopify stores, mid-tier purchases ($100-500)
Why This BIN?
- Chase Sapphire is a premium travel card. Normal spending includes random purchases at various amounts.
- Visa has the widest merchant acceptance.
- The $100-500 range is normal for this card type — won't trigger unusual spending alerts.
- Chase's fraud detection is moderate (not as aggressive as Citibank or Amex).
Alternative BINs for Different Scenarios:
| Scenario | Recommended BIN | Bank | Why |
| Digital goods | 556731 | Cap One QS | Less AVS scrutiny, often non-3DS |
| High-value ($500+) | 414720 | Chase Sapphire | Higher limits, premium travel card |
| EU merchant | 491700 | Barclays | EU-issued, less cross-border flags |
| Testing/checking | 440000 | Visa Gift | Cheap, high auth rate for testing |
| Recurring billing | 462222 | BoA Cash Rewards | Less velocity detection |
2.3 — SITE RECONNAISSANCE
You don't just card a site because someone said it's "cardable." You recon it first.
Step-by-Step Site Recon:
- Open the site in a clean browser (not your anti-detect profile yet)
- Check payment methods: Do they accept Visa/Mastercard directly? Or only PayPal?
- Test checkout flow: Add something to cart, go to checkout, see what fields are required
- Check for 3DS: Some sites show "Verified by Visa" during checkout
- Check shipping: Do they ship to freight forwarders? PO boxes?
- Check AVS strength: Does the checkout require exact ZIP? Full address?
- Read their fraud policy: Some sites have obvious fraud detection language
- Look for reviews: Search "[sitename] cardable" on forums
- Check return policy: Good return policy = easier to liquidate if something goes wrong
- Test with a real card first: If you have a prepaid card, run a small test purchase to see their auth flow
Signs a Site is Cardable:
- No 3DS popup during checkout
- Accepts credit cards directly (not PayPal-only)
- No AVS enforcement (you can put any address)
- Ships internationally or to freight forwarders
- Sells digital goods (codes, subscriptions) — instant delivery
- Small to medium business (not Amazon/Walmart scale)
- Shopify-based (easy to card)
- Older site with outdated security
- No CAPTCHA during checkout
2.4 — ANTI-DETECT BROWSER CONFIGURATION
Creating the Profile:
Code:
Profile Name: [Drop City] - [Site Name] - [Date]
OS: Windows 11 (spoofed if on Mac/Linux)
Browser: Chrome 125 (latest stable)
Resolution: 1920x1080
Timezone: Auto-detect from IP
Geolocation: Match proxy location
Language: en-US (matching IP region)
Fonts: US Windows default pack
WebGL: Intel or NVIDIA (spoof vendor)
Canvas: Noise added (0.1-0.3 level)
Audio: Noise added
WebRTC: Disabled
Portscan: Blocked
Plugins: Flash blocked, Java blocked
Cookies: Enabled (important!)
Proxy type: SOCKS5
Proxy: [Your residential proxy IP:port]
Proxy auth: username:password
Testing Your Profile:
Go to Browserleaks - Check your browser for privacy leaks and check:
- Your IP shows the correct city (not just country)
- Timezone matches IP location
- No WebRTC leaks (your real IP hidden)
- Canvas fingerprint is unique and spoofed
- Font fingerprint looks normal (not too many/too few fonts)
- User agent matches what you set
2.5 — THE LIVE CHECKOUT FLOW
This is it. The moment of truth. I'll document every click.
TIME TO EXECUTE — 28-Minute Session:
Code:
T+0:00 — Open anti-detect browser profile
T+0:01 — Load target site URL
T+0:03 — Browse site naturally (3-4 product pages, read descriptions)
T+0:05 — Add item to cart
T+0:06 — View cart (don't rush to checkout)
T+0:07 — Click "Proceed to Checkout"
T+0:08 — Enter email (burner, matches cardholder name)
T+0:09 — Enter shipping address (drop address)
T+0:11 — Select shipping method (standard, not overnight)
T+0:13 — Enter billing address (CARDHOLDER address, drop might differ)
T+0:15 — Enter card details:
- Card number: [from vendor]
- Expiry: MM/YY
- CVV: 3 digits (Amex: 4)
- Name on card: EXACTLY as on card
T+0:17 — Double check EVERYTHING before submit
T+0:18 — Click "Place Order"
T+0:19 — WAIT. Do not refresh. Do not click again.
T+0:19-0:45 — Processing... (this is the longest 30 seconds of your life)
T+0:45 — [SUCCESS] Order confirmation screen
T+0:46 — Screenshot the confirmation
T+0:47 — Check email for confirmation receipt
T+0:50 — Close profile. Log everything.
During the Wait (Critical):
- If you get an error, do NOT retry with the same card
- Close the profile entirely
- Create a NEW profile for the next attempt
- Note the error code
2.6 — HANDLING 3DS VERIFICATION
If you hit a 3DS page, you have options:
Option A: SMS Code to Cardholder
- If you have the fullz with phone access — enter the code
- If you don't — skip this card
- DO NOT try to guess the code
Option B: Skip and Try Another BIN
- Some BINs are non-3DS
- Chase, Capital One, and Discover have lower 3DS rates than Amex or Citibank
- Switch to a different BIN and try again
Option C: 3DS Bypass Techniques (Advanced)
- Amount splitting: Some merchants don't trigger 3DS below $50. Split your purchase.
- Cardholder portal: If you have fullz, log into the cardholder's online banking and pre-authorize the transaction. Some banks let you whitelist merchants.
- Merchant-specific bypass: Some merchants have a "skip verification" checkbox during checkout. Look for it.
Code:
- Device fingerprint
- IP geolocation
- Previous transactions from this device
- Cardholder's typical spending pattern
- Time since card was added to wallet/account
- Browser language inconsistencies (JS vs headers)
- Billing address distance from IP location
2.7 — POST-PURCHASE MANAGEMENT[/SITE]
Immediately After Success:
- Screenshot every confirmation email
- Check the order status on the merchant site (use the anti-detect profile)
- If it says "Pending Review" — don't panic. 30-40% of first orders go to manual review.
- If it says "Processing" or "Shipped" — you're in the clear
- Track the shipment — use a tracking aggregator
If Order Goes to Review:
- Don't contact customer support unless absolutely necessary
- If they email asking for verification — ignore and let the order cancel
- Chargeback risk: if the cardholder notices and files a chargeback, the merchant eats the loss
- You don't get paid until the chargeback window expires (typically 30-120 days depending on the bank)
Shipping Options:
| Method | Risk Level | Cost | Best For |
| Own address[/B] | Very High[/B] | Free[/B] | Nothing. Never do this.[/B] |
| Friend/relative[/B] | High[/B] | Free[/B] | Small amounts, trusted people[/B] |
| Abandoned house[/B] | Medium[/B] | Free[/B] | Parcel pickup before owner notices[/B] |
| Freight forwarder[/B] | Low[/B] | $10-20/pkg[/B] | US → International, high volume[/B] |
| Virtual mailbox[/B] | Low-Mid[/B] | $10/mo + per pkg[/B] | US-only, professional setup[/B] |
| Drop address[/B] | Medium[/B] | Varies[/B] | 10-20% to the drop owner[/B] |
2.8 — TROUBLESHOOTING DECLINES
Every decline tells you something. Here's the complete decision tree:
Error Code Reference:
| Error Message | What It Means | What To Do |
| "Your card was declined"[/B] | Generic decline, could be anything[/B] | Try a different card or BIN[/B] |
| "Card not supported"[/B] | Merchant doesn't accept this card type[/B] | Use a Visa instead of Amex/MC[/B] |
| "Insufficient funds"[/B] | Card has no available credit[/B] | Use a different card[/B] |
| "CVV mismatch"[/B] | Wrong CVV entered[/B] | Re-check CVV from vendor, retry[/B] |
| "Do not honor"[/B] | Bank refused the transaction[/B] | High-risk marker on this BIN, switch BINs[/B] |
| "Pick up card"[/B] | Card reported stolen/lost[/B] | Dispose of this card, don't retry[/B] |
| "3DS Required"[/B] | Bank requires additional verification[/B] | Try non-3DS BIN or use SMS access[/B] |
| "AVS mismatch"[/B] | Billing address doesn't match[/B] | Use exact billing address from fullz[/B] |
| "Transaction not allowed"[/B] | Card type can't be used for this purchase[/B] | Some cards block online purchases[/B] |
| "Velocity limit reached"[/B] | Too many attempts from this IP/device[/B] | New profile, new proxy, wait 24h[/B] |
The Decline Decision Tree:
Code:
Card Declined
│
├─ Was it instant (under 3 seconds)?
│ ├─ YES → BIN is likely dead or AVS failed
│ │ → Check BIN validity, try different address
│ │ → If still instant: BIN is burned, discard
│ │
│ └─ NO (3-15 seconds processing) → Card may be valid
│ → Bank is assessing risk factors
│ → Try different proxy in same city
│ → Check if 3DS was triggered
│ → Retry with fresh fingerprint
│
├─ Was 3DS triggered?
│ ├─ YES → Need SMS access or non-3DS card
│ └─ NO → Proceed with other fixes
│
├─ Check AVS response
│ ├─ Match → Problem is elsewhere
│ └─ Mismatch → Update billing address
│
├─ Check proxy quality
│ ├─ Clean → Look at card/merchant
│ └─ Flagged → New proxy needed
│
└─ Last resort: try same card on DIFFERENT merchant
├─ Works → Original merchant is the problem
└─ Fails → Card is dead
2.9 — CARDING SPECIFIC PLATFORMS
Shopify Stores:
- Shopify is the most cardable platform in 2026
- Fraud detection depends on the store owner's setup (often minimal)
- Most Shopify stores don't use 3DS
- Check if the store uses Shopify Payments or a third-party gateway
- Shopify Payments = higher approval rate
- Avoid stores that have Shopify Flow fraud prevention enabled
Amazon:
- Amazon has some of the best fraud detection in the world
- New accounts are flagged immediately for unusual payment behavior
- Amazon tracks device fingerprints aggressively
- Method: Aged accounts (1+ year) with legitimate purchase history
- Gift card balance = easier than credit card on Amazon
- Never card a new Amazon account with a CC — use gift card balance first
- Amazon Fresh/Whole Foods delivery has lower fraud detection
Digital Goods (Hosting, VPNs, SaaS):
- Digital goods are the safest carding targets
- No shipping address needed
- Instant delivery = instant liquidation
- Hosting companies (DigitalOcean, Linode, Vultr) often have weak payment verification
- VPN providers are easy to card
- SaaS subscriptions (Canva, Spotify, Netflix) — low fraud flags
- Downside: Payouts are smaller per transaction
EU Merchants:
- EU merchants almost always require 3DS — stronger regulations
- Exception: Small EU merchants using PayPal or Stripe without 3DS
- EU cards work better on EU sites (lower cross-border flags)
- UK is separate from EU post-Brexit — treat as different region
- German merchants are particularly strict
- Eastern European merchants are more cardable
2.10 — SCALING UP
Once you've completed your first successful transactions, it's time to scale.
From 1 Transaction/Day to 10/Day:
- Profile templates: Create reusable anti-detect profiles for each target region
- Proxy pools: Maintain a pool of 50+ residential proxies in different cities
- BIN rotation: Don't use the same BIN range for consecutive transactions
- Site rotation: Cycle through 20-30 tested sites
- Scheduled execution: Run transactions in batches at different times of day
- Record keeping: Track every attempt in a spreadsheet (card, site, result, error code)
- Automation: Use Puppeteer/Selenium for repetitive checkout flows
- Team: Consider hiring a VA to handle order management while you focus on transactions
Record Keeping Template:
Code:
Date | BIN | Site | Amount | Proxy IP | Result | Error | Notes
07/28|414720 | shopx.com| $249 | 192.168.x.x | Success | N/A | Shipped 07/30
07/28|556731 | storey.co| $89 | 10.0.0.x | Decline | 3DS | Need non-3DS BIN
07/29|462222 | gift.com | $500 | 172.16.x.x | Success | N/A | Digital codes
07/29|491700 | eu-shop | €150 | 87.x.x.x | Decline | AVS | Wrong billing ZIP
END OF PART 2
Continue to Part 3: Cashout & Monetization — converting carded goods into clean, spendable cash.
Continue to Part 3: Cashout & Monetization — converting carded goods into clean, spendable cash.