
How to detect click farms
What a click farm is, how phone farms mass-produce fake installs, signups, and clicks, and how the devices behind that activity cluster back to one operation.

Pavel Nuryieu is Head of Research at ShieldLabs, where he studies how anti-detect browsers, proxies, and other anonymity tools work, and how detection keeps pace. He has spent close to a decade researching device fingerprinting and online fraud techniques.

What a click farm is, how phone farms mass-produce fake installs, signups, and clicks, and how the devices behind that activity cluster back to one operation.

How to prevent bonus abuse in iGaming: the signals that reveal one person behind many accounts, how casinos spot multiple accounts, and how to stop it.

VPN vs proxy vs Tor: how each hides traffic, what each one still reveals, and how a detection layer tells them apart at the network level.

How to prevent gaming fraud: account theft and resale, real money trading farms, cheating and smurfing, and the device signals that link the accounts.

Google retired the Privacy Sandbox in October 2025 and third-party cookies are staying in Chrome. What it was, why it ended, and what it means for fraud.

iCloud Private Relay hides a Safari user's IP, but Apple publishes its egress ranges, so it is identifiable. What it is and how to read it for fraud.

How to prevent Sybil attacks: the defenses across the protocol and application layers, and how to catch one actor running many wallets or accounts at the frontend.

What passwordless authentication is, how it works, the main methods from passkeys to magic links, its benefits and limits, and where device signals fit.

Account recovery fraud is how attackers bypass strong login by abusing the reset flow. How it works, why recovery is the weak point, and how to defend it.

What trial farming and credit farming mean on an AI product, not the gaming kind: how one operator drains free compute credits, and where it is caught.

What device-based authentication is, how recognizing a trusted device makes login transparent, how it differs from passkeys and cookies, and where it fits.

How adaptive (risk-based) authentication works, the signals it weighs, and how recognizing the trusted device decides when to step up and when to let a user through.

How to prevent free-trial abuse: what it costs you, the signals that flag a recycled trial, and a playbook to stop it at signup without blocking real users.

How ban evasion detection works: why account-only bans fail, the signals that re-identify a returning banned user, and how detection ties a new signup to the old account.

Anti-fingerprint browsers spoof canvas, WebGL, fonts, and TLS to break recognition. How to detect them in 2026: the fingerprinting methods and the tells they leave.

What browser spoofing is, what attackers fake (user agent, OS, screen, timezone), and how a spoofed browser betrays itself through signals that disagree.

Detecting Tor traffic is easy because exit nodes are public. The hard part is acting on it without blocking real users. How web detection actually works.

WebGL fingerprinting identifies a device by how its GPU renders 3D graphics. How it works, what it reveals, and how it differs from canvas.

Font fingerprinting identifies a device by which fonts are installed, read from how text renders. How it works, what it reveals, and how stable it is.

Audio fingerprinting identifies a device by how it processes a sound signal in the browser. How it works, what it reveals, and how stable it is.

Impossible travel detection flags an account logging in from two far-apart places. Why velocity alone over-fires on VPNs, and how the device fixes it.

What a residential proxy is, where the home IPs come from, why IP checks miss them, and how residential proxy detection actually works without relying on the address.

Browser fingerprinting identifies a device from 100+ datapoints. Learn how canvas, WebGL, and IP signals work, plus detection methods and countermeasures.

Canvas fingerprinting identifies a browser by how it renders a hidden image. How it works, what it reveals, how stable it is, and its role in fraud detection.

The main browser fingerprinting techniques: canvas, WebGL, audio, fonts, TLS (JA3/JA4), and more, what each one reads and how stable it is.

Anti-detect browsers fake a new device per profile to power multi-accounting. How to detect them: the signals that expose them and why no one check is enough.