Fraud is a Business

β–Ά Watch (2:07)

Fraud operates as a profit-driven business with SOPs and runbooks. Photos from Wired show fraud centers in Southeast Asia with whiteboards tracking successful scams and a gong for big wins. Attackers use B2B SaaS-style tooling with landing pages, pricing tiers, and documentation. The talk shows examples of anti-detection tools that look exactly like legitimate SaaS products. Defenders who ignore this ecosystem play chess blindfolded.

Residential Proxies and CAPTCHA Solvers

β–Ά Watch (10:19)

Residential proxies route traffic through real home IPs, costing $2.50 per gigabyte. These IPs are not flagged as data center or VPN, making them harder to block. Carrier-grade NAT means one IP can serve thousands of users, so banning an IP risks blocking real customers. CAPTCHA solving services cost $1 per 1,000 solves. They started as two-sided marketplaces but now use dedicated tooling. Prices converge around $1–$2 per thousand. This is a commoditized offering.

Anti-Detect Browsers and Device Farms

β–Ά Watch (19:10)

Anti-detect browsers are Chromium forks modified to spoof fingerprints. They allow bulk profile creation for multi-accounting. Pricing starts at €5.85 per month for 10–50 profiles. Price does not correlate with stealth quality. Device farms are racks of real phones, rented for thousands per month. One A16Z-backed startup builds phone farms for fake TikTok content. These tools make detection extremely difficult for defenders.

Breaking the Attacker’s ROI

β–Ά Watch (22:35)

Attackers scale fraud with bots. A $2 loss per free trial becomes $20,000 per day at 10,000 trials. Defenders must break ROI by reducing payout, increasing time, or increasing cost. Adding a CAPTCHA adds 1/10 cent per attempt. Even cheap bypasses add up. Swiss cheese model: overlapping layers that are not bypassed the same way. Slowing payouts with waiting periods also reduces ROI. Attackers will move to easier targets.

Q&A

How does the CAPTCHA get passed on to the solver? Capture the HTML/JavaScript environment and send to solver, or generate reCAPTCHA tokens directly. β–Ά Watch (27:45)

Why doesn’t anyone go after the financial infrastructure of these fraud B2B SaaS apps? Dual-use services with legal teams; they claim KYC; fraud also hits AWS. β–Ά Watch (28:57)

How do AI agents evolve account takeovers and CAPTCHA solving? VLMs can solve CAPTCHAs but cost 100x more; coding agents write deterministic bypasses; agentic traffic looks like bot attacks, requiring OAuth consent scopes. β–Ά Watch (30:05)

Notable Quotes

These are industrialized tools that are used at scale. Bobbie Chen Β· β–Ά Watch (6:40)

Price has almost no correlation with stealth quality. Bobbie Chen Β· β–Ά Watch (21:19)

even though attackers can and do buy off-the-shelf evasion tooling, that still adds to their cost. Bobbie Chen Β· β–Ά Watch (26:22)

It’s like you’re playing chess blindfolded. Bobbie Chen Β· β–Ά Watch (8:53)

Key Takeaways

  • Fraud operates as a profit-driven business with commoditized tooling.
  • Residential proxies and CAPTCHA solvers cost pennies per use.
  • Defenders must break attacker ROI through layered defenses.