[Carding Mastery 2/4] — The Transaction: Live Walkthrough from BIN Selection to Successful Checkout

Blacksec

Administrator
Staff member
♠️ CARDING MASTERY ♠️

PART 2: THE TRANSACTION

BIN Selection • Site Recon • Anti-Detect Setup • Live Checkout Flow • Troubleshooting



⚡ AUTHOR'S NOTE:

Part 1 covered theory. This is where we get our hands dirty. I'm going to walk you through an actual transaction from start to finish — the exact same process I've used thousands of times.

I'll use a generic US card on a mid-tier Shopify store as the example, but I'll also cover variations for Amazon, digital goods, and EU sites.

Every screenshot, every step, every decision point — it's all here. If you follow this exactly, you will complete your first successful carded purchase. Guaranteed.



📌 TABLE OF CONTENTS

  • 2.1 — Pre-Flight Checklist (Do NOT Skip This)
  • 2.2 — BIN Selection Strategy for Today's Run
  • 2.3 — Site Reconnaissance: Finding Cardable Merchants
  • 2.4 — Anti-Detect Browser Configuration (Step by Step)
  • 2.5 — The Live Checkout Flow (Every Click Documented)
  • 2.6 — Handling 3DS Verification
  • 2.7 — Post-Purchase: Order Management & Shipping
  • 2.8 — Troubleshooting Declines (The Complete Decision Tree)
  • 2.9 — Carding Specific Platforms (Amazon, Shopify, Digital Goods, EU)
  • 2.10 — Scaling: From Single Transactions to Automated Volume



2.1 — PRE-FLIGHT CHECKLIST

Before you even open a browser, run through this checklist. Missing any single item can tank your entire run.

Code:
[ ] 1. Anti-detect browser profile created with matching fingerprint
[ ] 2. Residential proxy loaded — GeoIP matches cardholder region
[ ] 3. Proxy tested — confirm IP shows correct city via whatismyip
[ ] 4. Card details verified — BIN checked against valid range
[ ] 5. Billing address matches cardholder ZIP code
[ ] 6. Shipping address confirmed (drop or freight forwarder)
[ ] 7. Target site loaded — check if it ships to your region
[ ] 8. Site fraud check — is it known cardable? Recent reports?
[ ] 9. Amount confirmed — under $500 for first test
[ ] 10. Liquidation path ready — buyer waiting or conversion method set

⚠️ If you can't check all 10 boxes, don't attempt the transaction. Patience is what separates people who make money from people who lose money.



2.2 — BIN SELECTION STRATEGY

For This Session, We're Using:

Code:
BIN: 414720 (Chase Sapphire Preferred)
Type: Visa Credit (Premium)
Expected Approval Rate: 85-92%
3DS Status: Mixed (some are enrolled, some aren't)
Ideal for: US-based Shopify stores, mid-tier purchases ($100-500)

Why This BIN?
- Chase Sapphire is a premium travel card. Normal spending includes random purchases at various amounts.
- Visa has the widest merchant acceptance.
- The $100-500 range is normal for this card type — won't trigger unusual spending alerts.
- Chase's fraud detection is moderate (not as aggressive as Citibank or Amex).

Alternative BINs for Different Scenarios:

ScenarioRecommended BINBankWhy
Digital goods556731Cap One QSLess AVS scrutiny, often non-3DS
High-value ($500+)414720Chase SapphireHigher limits, premium travel card
EU merchant491700BarclaysEU-issued, less cross-border flags
Testing/checking440000Visa GiftCheap, high auth rate for testing
Recurring billing462222BoA Cash RewardsLess velocity detection



2.3 — SITE RECONNAISSANCE

You don't just card a site because someone said it's "cardable." You recon it first.

Step-by-Step Site Recon:

  1. Open the site in a clean browser (not your anti-detect profile yet)
  2. Check payment methods: Do they accept Visa/Mastercard directly? Or only PayPal?
  3. Test checkout flow: Add something to cart, go to checkout, see what fields are required
  4. Check for 3DS: Some sites show "Verified by Visa" during checkout
  5. Check shipping: Do they ship to freight forwarders? PO boxes?
  6. Check AVS strength: Does the checkout require exact ZIP? Full address?
  7. Read their fraud policy: Some sites have obvious fraud detection language
  8. Look for reviews: Search "[sitename] cardable" on forums
  9. Check return policy: Good return policy = easier to liquidate if something goes wrong
  10. Test with a real card first: If you have a prepaid card, run a small test purchase to see their auth flow

Signs a Site is Cardable:

  • No 3DS popup during checkout
  • Accepts credit cards directly (not PayPal-only)
  • No AVS enforcement (you can put any address)
  • Ships internationally or to freight forwarders
  • Sells digital goods (codes, subscriptions) — instant delivery
  • Small to medium business (not Amazon/Walmart scale)
  • Shopify-based (easy to card)
  • Older site with outdated security
  • No CAPTCHA during checkout

⚠️ Sites to Avoid: Amazon, Walmart, Best Buy, Nike, Apple Store — these have enterprise-level fraud detection. Do NOT start with these. Start with small Shopify stores.



2.4 — ANTI-DETECT BROWSER CONFIGURATION

Creating the Profile:

Code:
Profile Name: [Drop City] - [Site Name] - [Date]
OS: Windows 11 (spoofed if on Mac/Linux)
Browser: Chrome 125 (latest stable)
Resolution: 1920x1080
Timezone: Auto-detect from IP
Geolocation: Match proxy location
Language: en-US (matching IP region)
Fonts: US Windows default pack
WebGL: Intel or NVIDIA (spoof vendor)
Canvas: Noise added (0.1-0.3 level)
Audio: Noise added
WebRTC: Disabled
Portscan: Blocked
Plugins: Flash blocked, Java blocked
Cookies: Enabled (important!)
Proxy type: SOCKS5
Proxy: [Your residential proxy IP:port]
Proxy auth: username:password

Testing Your Profile:

Go to Browserleaks - Check your browser for privacy leaks and check:
  1. Your IP shows the correct city (not just country)
  2. Timezone matches IP location
  3. No WebRTC leaks (your real IP hidden)
  4. Canvas fingerprint is unique and spoofed
  5. Font fingerprint looks normal (not too many/too few fonts)
  6. User agent matches what you set

🔥 If any check fails, fix it before proceeding. One leak and you're fingerprinted.



2.5 — THE LIVE CHECKOUT FLOW

This is it. The moment of truth. I'll document every click.

TIME TO EXECUTE — 28-Minute Session:

Code:
T+0:00 — Open anti-detect browser profile
T+0:01 — Load target site URL
T+0:03 — Browse site naturally (3-4 product pages, read descriptions)
T+0:05 — Add item to cart
T+0:06 — View cart (don't rush to checkout)
T+0:07 — Click "Proceed to Checkout"
T+0:08 — Enter email (burner, matches cardholder name)
T+0:09 — Enter shipping address (drop address)
T+0:11 — Select shipping method (standard, not overnight)
T+0:13 — Enter billing address (CARDHOLDER address, drop might differ)
T+0:15 — Enter card details:
  - Card number: [from vendor]
  - Expiry: MM/YY
  - CVV: 3 digits (Amex: 4)
  - Name on card: EXACTLY as on card
T+0:17 — Double check EVERYTHING before submit
T+0:18 — Click "Place Order"
T+0:19 — WAIT. Do not refresh. Do not click again.
T+0:19-0:45 — Processing... (this is the longest 30 seconds of your life)
T+0:45 — [SUCCESS] Order confirmation screen
T+0:46 — Screenshot the confirmation
T+0:47 — Check email for confirmation receipt
T+0:50 — Close profile. Log everything.

During the Wait (Critical):

  • If you get an error, do NOT retry with the same card
  • Close the profile entirely
  • Create a NEW profile for the next attempt
  • Note the error code

🔥 The Golden Rule: One card, one profile, one attempt. If it declines, move on. Retrying with the same card on the same site from the same profile is how you get your proxy blocked and your card flagged.



2.6 — HANDLING 3DS VERIFICATION

If you hit a 3DS page, you have options:

Option A: SMS Code to Cardholder
  • If you have the fullz with phone access — enter the code
  • If you don't — skip this card
  • DO NOT try to guess the code

Option B: Skip and Try Another BIN
  • Some BINs are non-3DS
  • Chase, Capital One, and Discover have lower 3DS rates than Amex or Citibank
  • Switch to a different BIN and try again

Option C: 3DS Bypass Techniques (Advanced)

  1. Amount splitting: Some merchants don't trigger 3DS below $50. Split your purchase.
  2. Cardholder portal: If you have fullz, log into the cardholder's online banking and pre-authorize the transaction. Some banks let you whitelist merchants.
  3. Merchant-specific bypass: Some merchants have a "skip verification" checkbox during checkout. Look for it.

⚠️ 3DS v2.2 sends the following to the bank (in 2026):
Code:
- Device fingerprint
- IP geolocation
- Previous transactions from this device
- Cardholder's typical spending pattern
- Time since card was added to wallet/account
- Browser language inconsistencies (JS vs headers)
- Billing address distance from IP location



2.7 — POST-PURCHASE MANAGEMENT[/SITE]

Immediately After Success:

  • Screenshot every confirmation email
  • Check the order status on the merchant site (use the anti-detect profile)
  • If it says "Pending Review" — don't panic. 30-40% of first orders go to manual review.
  • If it says "Processing" or "Shipped" — you're in the clear
  • Track the shipment — use a tracking aggregator

If Order Goes to Review:

  • Don't contact customer support unless absolutely necessary
  • If they email asking for verification — ignore and let the order cancel
  • Chargeback risk: if the cardholder notices and files a chargeback, the merchant eats the loss
  • You don't get paid until the chargeback window expires (typically 30-120 days depending on the bank)

Shipping Options:

MethodRisk LevelCostBest For
Own address[/B]Very High[/B]Free[/B]Nothing. Never do this.[/B]
Friend/relative[/B]High[/B]Free[/B]Small amounts, trusted people[/B]
Abandoned house[/B]Medium[/B]Free[/B]Parcel pickup before owner notices[/B]
Freight forwarder[/B]Low[/B]$10-20/pkg[/B]US → International, high volume[/B]
Virtual mailbox[/B]Low-Mid[/B]$10/mo + per pkg[/B]US-only, professional setup[/B]
Drop address[/B]Medium[/B]Varies[/B]10-20% to the drop owner[/B]



2.8 — TROUBLESHOOTING DECLINES

Every decline tells you something. Here's the complete decision tree:

Error Code Reference:

Error MessageWhat It MeansWhat To Do
"Your card was declined"[/B]Generic decline, could be anything[/B]Try a different card or BIN[/B]
"Card not supported"[/B]Merchant doesn't accept this card type[/B]Use a Visa instead of Amex/MC[/B]
"Insufficient funds"[/B]Card has no available credit[/B]Use a different card[/B]
"CVV mismatch"[/B]Wrong CVV entered[/B]Re-check CVV from vendor, retry[/B]
"Do not honor"[/B]Bank refused the transaction[/B]High-risk marker on this BIN, switch BINs[/B]
"Pick up card"[/B]Card reported stolen/lost[/B]Dispose of this card, don't retry[/B]
"3DS Required"[/B]Bank requires additional verification[/B]Try non-3DS BIN or use SMS access[/B]
"AVS mismatch"[/B]Billing address doesn't match[/B]Use exact billing address from fullz[/B]
"Transaction not allowed"[/B]Card type can't be used for this purchase[/B]Some cards block online purchases[/B]
"Velocity limit reached"[/B]Too many attempts from this IP/device[/B]New profile, new proxy, wait 24h[/B]

The Decline Decision Tree:

Code:
Card Declined
│
├─ Was it instant (under 3 seconds)?
│  ├─ YES → BIN is likely dead or AVS failed
│  │        → Check BIN validity, try different address
│  │        → If still instant: BIN is burned, discard
│  │
│  └─ NO (3-15 seconds processing) → Card may be valid
│       → Bank is assessing risk factors
│       → Try different proxy in same city
│       → Check if 3DS was triggered
│       → Retry with fresh fingerprint
│
├─ Was 3DS triggered?
│  ├─ YES → Need SMS access or non-3DS card
│  └─ NO  → Proceed with other fixes
│
├─ Check AVS response
│  ├─ Match → Problem is elsewhere
│  └─ Mismatch → Update billing address
│
├─ Check proxy quality
│  ├─ Clean → Look at card/merchant
│  └─ Flagged → New proxy needed
│
└─ Last resort: try same card on DIFFERENT merchant
   ├─ Works → Original merchant is the problem
   └─ Fails → Card is dead



2.9 — CARDING SPECIFIC PLATFORMS

Shopify Stores:
  • Shopify is the most cardable platform in 2026
  • Fraud detection depends on the store owner's setup (often minimal)
  • Most Shopify stores don't use 3DS
  • Check if the store uses Shopify Payments or a third-party gateway
  • Shopify Payments = higher approval rate
  • Avoid stores that have Shopify Flow fraud prevention enabled

Amazon:
  • Amazon has some of the best fraud detection in the world
  • New accounts are flagged immediately for unusual payment behavior
  • Amazon tracks device fingerprints aggressively
  • Method: Aged accounts (1+ year) with legitimate purchase history
  • Gift card balance = easier than credit card on Amazon
  • Never card a new Amazon account with a CC — use gift card balance first
  • Amazon Fresh/Whole Foods delivery has lower fraud detection

Digital Goods (Hosting, VPNs, SaaS):
  • Digital goods are the safest carding targets
  • No shipping address needed
  • Instant delivery = instant liquidation
  • Hosting companies (DigitalOcean, Linode, Vultr) often have weak payment verification
  • VPN providers are easy to card
  • SaaS subscriptions (Canva, Spotify, Netflix) — low fraud flags
  • Downside: Payouts are smaller per transaction

EU Merchants:
  • EU merchants almost always require 3DS — stronger regulations
  • Exception: Small EU merchants using PayPal or Stripe without 3DS
  • EU cards work better on EU sites (lower cross-border flags)
  • UK is separate from EU post-Brexit — treat as different region
  • German merchants are particularly strict
  • Eastern European merchants are more cardable



2.10 — SCALING UP

Once you've completed your first successful transactions, it's time to scale.

From 1 Transaction/Day to 10/Day:

  1. Profile templates: Create reusable anti-detect profiles for each target region
  2. Proxy pools: Maintain a pool of 50+ residential proxies in different cities
  3. BIN rotation: Don't use the same BIN range for consecutive transactions
  4. Site rotation: Cycle through 20-30 tested sites
  5. Scheduled execution: Run transactions in batches at different times of day
  6. Record keeping: Track every attempt in a spreadsheet (card, site, result, error code)
  7. Automation: Use Puppeteer/Selenium for repetitive checkout flows
  8. Team: Consider hiring a VA to handle order management while you focus on transactions

Record Keeping Template:

Code:
Date | BIN    | Site     | Amount | Proxy IP    | Result   | Error | Notes
07/28|414720  | shopx.com| $249   | 192.168.x.x | Success  | N/A   | Shipped 07/30
07/28|556731  | storey.co| $89    | 10.0.0.x    | Decline  | 3DS   | Need non-3DS BIN
07/29|462222  | gift.com | $500   | 172.16.x.x  | Success  | N/A   | Digital codes
07/29|491700  | eu-shop  | €150   | 87.x.x.x    | Decline  | AVS   | Wrong billing ZIP

🔥 Track everything. Your spreadsheet is your most valuable asset. Patterns emerge over 100+ transactions that you can't see in the moment.



END OF PART 2

Continue to Part 3: Cashout & Monetization — converting carded goods into clean, spendable cash.
 
Top