How do bots exploit marketplace promo codes and coupons?
Code harvesting from coupon sites and APIs
The cheapest source of working codes is the open web. Coupon aggregator sites publish codes the moment shoppers share them, and scrapers watch those pages continuously, extract new codes within minutes, and feed them into checkout bots. Marketplaces that hand out exclusive codes to partners or affiliates find those codes public within hours of first use, because one leak is enough and the aggregators never take them down.
The subtler leak is the marketplace's own API. Many storefronts return a full list of valid promotions in the cart or pricing endpoint, or respond differently to a valid code versus an invalid one in a way that is trivially distinguishable. Attackers enumerate the response space and learn the working codes without guessing. Rate limiting the checkout page does nothing when the pricing API answers for free. The fix is boring but effective: generic error responses, no promotion enumeration in public endpoints, and server-side code validity checks that reveal nothing to a scanner.
Brute-force code guessing at checkout
When harvesting is not enough, bots guess. Short alphanumeric codes, especially ones with predictable structure like SAVE20 or FALL25 followed by a few digits, are enumerable. A bot submits thousands of combinations through the checkout code field, rotating IPs and sessions to stay under the rate limit. Most marketplaces allow dozens of attempts per session before throttling, which is more than enough when the code space is small and the bot farm is large.
The detection signal is the attempt pattern, not any single try. A real shopper types one or two codes and either succeeds or gives up. A guessing operation shows hundreds of failed attempts with machine-regular timing, identical cart contents, and session fingerprints that cluster around the same infrastructure. The defense is to throttle attempts per device and session, impose increasing delays after a few failures, and treat high-failure sessions as bot traffic worth scoring rather than shoppers worth converting.
Automated checkout that spends codes at scale
Finding a working code is only half the operation. The other half is spending it, and that is where checkout bots come in. They create accounts in bulk, often through aged-account pipelines, claim new-user or single-use codes, and check out with stored payment methods or gift cards. Each account is cheap and disposable, so losing a few to fraud detection is just a cost of doing business. The marketplace sees a spike in new-user discount usage that looks like a successful campaign until someone checks the retention of those accounts.
This is also how single-use codes get defeated. A single-use code tied to an account is useless as a defense when accounts are infinite. The working controls pair the code with account-level abuse signals: email age, device reuse across accounts, payment method reuse, and signup velocity from the same infrastructure. A single-use code is only single-use if the identity behind it is unique.
Stacking and combination exploits
Sophisticated operators look for codes that combine. A percentage-off code plus a free-shipping threshold plus a cashback offer can turn a normal margin into a negative one, and bots find those combinations systematically by testing every published code against every other one at checkout. Marketplaces that validate codes independently, one at a time, never see the interaction that a bot testing thousands of combinations finds in minutes.
The practical answer is server-side combination rules that are tested against themselves. Before any promotion goes live, an automated check should try the new code against every active code and flag combinations that stack in unexpected ways. Humans approve promotions thinking about the average shopper. Bots shop as the worst-case shopper, and they run the math faster.
What actually reduces promo code abuse
No single control does it. The working stack is layered: longer, random code formats that resist guessing, no promotion enumeration in public APIs, attempt throttling per session and device with increasing delays, and checkout-time scoring that weights account age, device reuse, and code-attempt history together. Coupon campaigns should be monitored for abuse signatures in the first hours, not at the monthly finance review, because bot operators spend fast and the damage is front-loaded.
The marketplaces that keep promo abuse under control treat codes as credentials: hard to guess, limited in attempts, monitored for reuse anomalies, and revoked quickly when abused. Promo codes are money with a marketing interface. Everything that protects money applies, and nothing about the marketing context makes the attacker less motivated.
Can you stop promo code guessing without hurting conversion?
Yes. Code attempts should be throttled per session and device, not per account, and suspicious sessions get a step-up check before another attempt is allowed. Legitimate shoppers try one or two codes and give up; bots try thousands. The behavior difference is large enough to separate cleanly.
Do single-use codes stop bot abuse?
They stop code sharing but not new-account abuse. Bot operators create fresh accounts, claim the single-use code, and check out. Single-use codes must be paired with account-level abuse detection to work.