100+ Configs • Carding • Email Checkers • Social Media • Streaming • Gift Cards • Crypto Exchanges
I've been building and collecting OpenBullet configs since OB1. This is my personal collection — all tested, all working as of July 2026. Configs are organized by category with notes on hit rates, proxy requirements, and expected output.
What you need: OpenBullet 2 (latest build), residential or semi-dedicated proxies, and time to run them.
Proxy requirements vary: Some configs work with datacenter IPs (email checkers), others need residential proxies (carding, streaming). Notes included with each config.
| Category | Configs | Proxy Type | Avg Hit Rate |
| Streaming Services | Netflix, Disney+, Hulu, HBO, Crunchyroll, Amazon Prime | Residential | 12-25% |
| Social Media | Instagram, Twitter/X, TikTok, Snapchat, OnlyFans | Mix (DC + Res) | 8-20% |
| Email Checkers | Gmail, Outlook, Yahoo, ProtonMail, AOL, Yandex | Datacenter OK | 15-30% |
| Gaming | Steam, Epic Games, Minecraft, Roblox, Riot | Residential | 5-18% |
| Carding / CC | Bin Checkers, Stripe, Auth Gateways, Gift Cards | Residential (BIN-matched) | Variable |
| Crypto | Binance, Coinbase, Kraken, Bybit, KuCoin | Residential | 3-12% |
| Premium Services | Canva Pro, ChatGPT, Midjourney, Adobe CC, NordVPN | Mix | 10-22% |
| Utilities | Proxies checkers, email verifiers, captcha solvers | Any | N/A (tools) |
CONFIG SETUP GUIDE
OpenBullet 2 Quick Start:
Code:
1. Download OpenBullet 2
- https://github.com/openbullet/openbullet2/releases
- Extract to C:\OB2\
2. Import configs
- Open OB2
- Go to Configs → Import
- Select the .loli files from this pack
- They'll appear in your config list
3. Set up proxies
- Go to Proxies → Import
- Format: ip:port or ip:port:user:pass
- Mark proxy type (HTTP/SOCKS4/SOCKS5)
- Check proxies → green = working
4. Load combos
- Go to Wordlist → Import
- Format: email:pass (one per line)
- Or: user:pass depending on config
5. Start checking
- Select config → Select wordlist → Select proxies
- Click "Start All"
- Monitor hits in real-time
6. Export results
- Hits are saved automatically in Results/
- Export to CSV or TXT
- Config-specific output in data/
Proxy Best Practices:
Code:
For maximum hit rates, use the right proxies:
Streaming (Netflix, Disney+, Hulu):
- Residential proxies from the target country (US for US content)
- Avoid DC IPs — they get blocked immediately
- Rotation: 1 proxy per 5-10 checks
Social Media (IG, Twitter, Snapchat):
- Semi-dedicated residential
- OOKLA speedtest: minimum 10mbps
- Rate limiting: 30 seconds between attempts per proxy
Email Checkers (Gmail, Outlook):
- Datacenter proxies work fine
- 1 proxy per 100-200 checks
- HTTP proxies OK
Carding configs:
- Premium residential only
- BIN-matched to country of card
- 1 proxy per 2-3 checks (high rotation)
- Use sticky sessions where possible
STREAMING CONFIGS
Netflix Premium Checker:
Code:
Config Name: Netflix_Premium_2026.loli
Endpoint: netflix.com/api/shakti/
Auth Type: Cookie + Basic Auth
Checks: Plan type, profile count, payment method
Output: Working/NoPlan/Expired/Failed
Hit Rate: 15-22% (residential proxies)
Speed: 8-12 checks per proxy per minute
What it checks:
- Subscription status (active, suspended, expired)
- Plan tier (Basic HD, Standard FHD, Premium UHD)
- Profiles available (counts as working based on plan)
- Payment method on file (card, PayPal, gift card)
Proxy: Residential only, country-matched to account
Output file:
- Working: netflix_hits.txt (with plan info)
- Contains: email:password:plan:payment_method
Disney+ Checker:
Code:
Config Name: DisneyPlus_Checker.loli
Endpoint: disneyplus.com/api/
Auth: Basic auth + bearer token extraction
Hit Rate: 20-35% (best among streaming services)
Speed: 15-20 checks per proxy per minute
Why Disney+ has higher hit rates:
- Shorter token expiry (less cached dead accounts)
- Higher credential reuse rate among users
- More recent combo dumps available
Proxy: Residential, US preferred (but most countries work)
Notes: This is the most profitable streaming checker currently
SOCIAL MEDIA CONFIGS
Instagram Checker (Login + Followers):
Code:
Config Name: IG_Login_Checker.loli
Endpoint: instagram.com/api/v1/
Auth: Username/password + challenge handling
Output: Working/Challenge/Bad/Failed
Hit Rate: 10-18%
Challenges:
- Instagram triggers phone/email verification on unfamiliar IPs
- Config includes challenge detection: marks as "Challenge" not "Bad"
- Manual verification needed for challenged accounts
Tips for higher IG hit rates:
- Use proxies from the same country as the account
- Warm up proxies (browse Instagram for 5 min before checking)
- Max 50 checks per proxy per day
- Rotate User-Agent with each request
Value:
- Working IG accounts sell for $2-5 each
- Accounts with 1k+ followers sell for $10-50
- Business accounts with verification: $100+
OnlyFans Checker (Premium):
Code:
Config Name: OnlyFans_Premium_Checker.loli
Endpoint: onlyfans.com/api/v2/
Auth: Bearer token (from email:pass login)
Output: Working/Free/Expired/Failed
Hit Rate: 5-12%
What it checks:
- Has active subscription (paid or free sub)
- Creator account (if user is a creator)
- Wallet balance (some have $)
- Cards on file (linked payment methods)
This is a high-value config:
- Creator accounts sell for $50-500
- Accounts with wallet balance are cashouts
- Subscribed accounts can download content
EMAIL CHECKERS
Gmail Validator (IMAP + SMTP):
Code:
Config Name: Gmail_IMAP_Validator.loli
Endpoint: imap.gmail.com (993)
Auth: XOAUTH2 / App Password
Output: Valid/Invalid/AppPassRequired
Hit Rate: 20-30%
Features:
- Checks if Gmail is accessible via IMAP
- Detects if app password is required (2FA enabled accounts)
- Checks inbox count (active vs abandoned)
- Returns: email:password:app_pass_status:inbox_count
Uses for valid GMails:
- PayPal accounts (most common email)
- Account recovery (reset passwords via Gmail)
- Sending spam (if SMTP enabled)
- Creating additional accounts on other platforms
ProtonMail Checker (Privacy Email):
Code:
Config Name: ProtonMail_Checker.loli
Endpoint: api.protonmail.ch
Auth: SRP (Secure Remote Password protocol — unique to Proton)
Output: Working/NoAccess/Failed
Hit Rate: 10-18%
ProtonMail is harder to check:
- SRP protocol (not basic HTTP auth)
- Rate limiting is aggressive
- Some accounts have PGP keys set (extra protection)
Value of ProtonMail accounts:
- Used by carders (privacy-focused)
- Often linked to darknet markets
- Accounts with verified phone: $10-15
- PM Business accounts: $20-30
GAMING CONFIGS
Steam Account Checker:
Code:
Config Name: Steam_Account_Checker.loli
Endpoint: steamcommunity.com
Auth: RSA-encrypted login (uses Steam's public key)
Output: Working/Guard/NoGames/Failed
Hit Rate: 5-12%
What it retrieves:
- SteamID (profile number)
- Library size (# of games)
- Account age (creation date)
- VAC status (banned/clean)
- Wallet balance (in cents)
- Steam Level
Steam Guard handling:
- Accounts with Steam Guard mobile: flagged as "Guard"
- These need Steam Guard code to access
- Some configs attempt to crack mobile auth: 2% success rate
- No-Guard accounts sell for premium
Pricing:
- Clean Steam accounts: $2-10
- Accounts with games: $5-50+
- CS2 ranked accounts: $15-40
- Rare game collections: $100+
CRYPTO EXCHANGE CONFIGS
Coinbase Checker:
Code:
Config Name: Coinbase_Balance_Checker.loli
Endpoint: api.coinbase.com
Auth: JWT token + 2FA challenge handling
Output: Working/2FA/Bad/Failed
Hit Rate: 3-8%
What it checks:
- Account balance (BTC, ETH, USDT, USDC)
- Transaction history (recent buys/sells)
- Verification level (KYC tier)
- Linked payment methods (bank, card)
This is a cashout config:
- Accounts with balance: drain via withdrawal
- Verified accounts: sell for $50-200
- Accounts with linked payment: high value
PREMIUM SERVICE CONFIGS
ChatGPT Plus / Pro Checker:
Code:
Config Name: ChatGPT_Plus_Checker.loli
Endpoint: api.openai.com/v1/
Auth: Bearer token (session-based)
Output: Working/Free/Expired/Failed
Hit Rate: 8-15%
Checks:
- Subscription plan (Free, Plus $20, Pro $200)
- API key access (if OpenAI API key exists)
- Usage history
Value:
- ChatGPT Plus accounts: $10-20
- ChatGPT Pro accounts: $50-100 (rare)
- Accounts with API credits: $20-100+
DOWNLOAD & SETUP
Code:
Config Pack Download:
MEGA: https://mega.nz/file/BlackSec_OB2_Configs_2026
Size: 8.4 MB (zip)
Password: OB2BlackSec2026
Includes:
- 127 configs (.loli files)
- README with per-config notes
- Edge profiles for challenge-free browsing
- Wordlist samples (2M combos for testing)
- Proxy list (2000 working SOCKS5, free tier — rotate quickly)
Installation:
1. Download the zip
2. Extract to C:\OB2\Configs\
3. Open OB2 → Configs → the configs will auto-load
4. Start checking
Configs that need API keys:
- Stripe carder: needs your Stripe API key (add in config settings)
- Binance checker: needs optional 2FA bypass config
- Gmail checker: requires App Password generation for 2FA accounts
Config updates:
- I'll post updates in this thread when endpoints change
- Some configs break when the service changes their API
- Check back every 2-4 weeks for updates
Questions about specific configs? Drop a reply. I answer within 48 hours.