<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Martin</title>
    <description>The latest articles on DEV Community by Martin (@debatly).</description>
    <link>https://dev.to/debatly</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4154410%2F354e1bc8-364c-4c4c-b698-3b58b4bacc61.png</url>
      <title>DEV Community: Martin</title>
      <link>https://dev.to/debatly</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/debatly"/>
    <language>en</language>
    <item>
      <title>Bots with VPNs are card-testing stolen cards on my SaaS. How did you fight it?</title>
      <dc:creator>Martin</dc:creator>
      <pubDate>Thu, 01 Oct 2026 10:17:22 +0000</pubDate>
      <link>https://dev.to/debatly/bots-with-vpns-are-card-testing-stolen-cards-on-my-saas-how-did-you-fight-it-1dbb</link>
      <guid>https://dev.to/debatly/bots-with-vpns-are-card-testing-stolen-cards-on-my-saas-how-did-you-fight-it-1dbb</guid>
      <description>&lt;p&gt;Hey everyone,&lt;/p&gt;

&lt;p&gt;I'm building &lt;a href="https://debatly.com" rel="noopener noreferrer"&gt;Debatly&lt;/a&gt;, an AI debate platform where you can create characters and let different AI models (OpenAI, Anthropic, Google) argue with each other or with you.&lt;/p&gt;

&lt;p&gt;Recently I ran into a problem I didn't expect this early: card testing.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happened
&lt;/h2&gt;

&lt;p&gt;I had a free trial that required a card. Right after I listed Debatly in a few AI and startup directories, I got 500+ trial signups paid with stolen cards. The traffic came mostly from Russia and Belarus, hidden behind VPNs and rotating IPs. The bots were checking whether the cards were valid and burning through trial credits at the same time.&lt;/p&gt;

&lt;p&gt;As a quick fix I removed the free trial completely and switched to paid only. It stopped the bleeding, but it also kills conversion for real users, so I don't want this to be the long term answer.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'd love to hear from you
&lt;/h2&gt;

&lt;p&gt;Have you dealt with card testing on a small SaaS? What actually worked?&lt;br&gt;
Did tools like Stripe Radar rules, 3D Secure on every payment, or a CAPTCHA (Turnstile, hCaptcha) on signup make a real difference?&lt;br&gt;
Is blocking VPN / datacenter IPs worth it, or does it hurt legit users too much?&lt;br&gt;
Any smarter way to offer a trial without a card (email verification, limited credits, rate limits per device) that bots can't easily farm?&lt;br&gt;
Did directory listings attract this kind of traffic for you too, or was I just unlucky?&lt;/p&gt;

&lt;p&gt;I'd really appreciate any war stories, configs or tools you'd recommend. Happy to share what I end up implementing in a follow-up post.&lt;/p&gt;

&lt;p&gt;Thanks! 🙏&lt;/p&gt;

</description>
      <category>security</category>
      <category>saas</category>
      <category>discuss</category>
    </item>
  </channel>
</rss>
