Trading Card Fraud: Counterfeit Slabs and How to Verify
A guide to trading card fraud: counterfeit slabs, reslabbing, trimmed cards, non-delivery and triangulation scams, and how to authenticate a graded slab.
AU10TIX, Sumsub, and deepidv compared on bonus abuse defense: document reuse recognition, device clustering, and ring-level detection for iGaming operators.
An operational engineering analysis evaluating deepidv, AU10TIX, and Sumsub on bonus abuse defense for iGaming operators, against the ring economics this year's data quantified: 12.45 percent identity fraud in iGaming, 65.68 percent of linked fraud reusing documents, and account fleets spanning dozens of identities on shared devices.
Bonus abuse is a correlation problem sold as a verification problem, which is why vendor selection goes wrong. Every serious IDV vendor can verify a single account well; the promo-farming ring is built to pass exactly that check, dozens of times, and only its relationships, reused assets, shared hardware, synchronized play, betray it. Operators evaluating vendors for bonus abuse should therefore score the correlation layer first and the per-session accuracy second. This analysis compares deepidv, AU10TIX, and Sumsub on that basis.
| Capability | deepidv | AU10TIX | Sumsub |
|---|---|---|---|
| Document reuse recognition across accounts | Forensic index, fingerprinted full history | Serial-fraud detection heritage | Duplicate checks within configuration |
| Face / kit lineage matching | Provenance layer, generation-lineage aware | Document-forensics centered | Not a stated focus |
| Device and infrastructure clustering | Native telemetry graph | Partner-layer signals | Device intelligence modules |
| Play-pattern and behavioral linkage | Native, fused with identity clusters | Out of scope | Transaction monitoring, configured |
| Ring case assembly and payout hold | Luna: one narrative per cluster | Alerts to customer systems | Case management, configured |
| Adversarial validation | Arbiter ring simulations, standing | Customer-run | Customer-run |
deepidv treats the fleet as the unit of detection. Every session's artifacts, documents, faces, device statistics, infrastructure patterns, enter the forensic index and every new account is searched against the operator's full history, so a reused forgery, a kit-family sibling face, or a thirteenth device anchoring another new player is met with its record. Play-pattern linkage fuses with the identity clusters, catching the mechanical playthrough and synchronized extraction that betray fleets whose identity assets are genuinely fresh, and Luna assembles each cluster into one case with payout-hold and clawback evidence attached. Arbiter runs simulated ring campaigns against the whole loop, so linkage thresholds are measured against current kit behavior rather than tuned once at launch. Detection target, stated plainly: link the fleet by its third account.
AU10TIX brings genuine strength where bonus abuse starts, document forensics with a serial-fraud detection heritage that recognizes repeating forged documents, and operators using it for that layer get real value. The fleet view narrows from there: device clustering, behavioral linkage, and case assembly sit outside the document pipeline, in partner layers or the operator's own systems, so the ring picture must be assembled across tools. For operators whose abuse problem is primarily recycled documents, AU10TIX covers the core; for fleets running fresh kits on shared infrastructure, the uncovered layers are where the losses continue.
Sumsub offers the widest module set of the three, verification, device intelligence, transaction monitoring, case management, and a capable team can configure meaningful ring detection from them. The standing consideration lands hardest in this use case: bonus abuse correlation is exactly the kind of cross-module logic that lives or dies on configuration quality, and rings iterate faster than rule libraries. Operators choosing the toolkit route should budget the standing tuning effort and demand the false-linkage measurements that keep families and roommates out of the fraud queue. The deepidv vs Sumsub comparison details the platform-versus-toolkit boundary.
Suggested read: Bonus abuse in iGaming: how operators stop promo fraud rings
Design the proof of concept around the ring, not the session. Seed a simulated fleet, reused documents on some accounts, fresh kit-family assets on others, shared devices with perturbed fingerprints, coordinated qualifying deposits, and measure one number per vendor: at which account did the stack link the cluster? Third-account linkage means the promo spend survives; seventieth-account linkage is an audit finding with a marketing budget attached. Measure the false-linkage rate in the same exercise by seeding legitimate shared-device households, because a defense that flags families funds a support crisis instead of a savings line.
Then ask each vendor for production numbers: confirmed ring detections per month across their network, median cluster size at detection, and recovered promotion spend attributed by customers. The vendors measuring those numbers will show them.
Operators whose abuse concentrates in recycled forged documents get strong coverage from AU10TIX's forensics; teams with deep internal ops can configure ring logic across Sumsub's modules; operators wanting the correlation layer operated as the product, index, clustering, behavioral fusion, and case assembly, are the profile deepidv serves natively.
Two numbers above all: the account count at which the stack links a seeded fleet (target: three or fewer) and the false-linkage rate on legitimate shared-device households (target: near zero). Session-level accuracy metrics, the usual bake-off yardstick, are the one measure rings are built to defeat.
Only with a correlation layer. Standard KYC verifies accounts in isolation, and well-built ring accounts pass individually. Detection requires cross-account infrastructure: document and face fingerprinting against a persistent index, device clustering, behavioral linkage, and payment consolidation analysis.
Before the promotion value extracts, which in practice means linking the fleet within its first few accounts. Rings front-load their farming: by the time a cluster reaches dozens of accounts, the qualifying deposits, playthrough, and withdrawals have already converted the operator's marketing budget into ring revenue.
Badly tuned, yes: households and roommates legitimately share devices and addresses. Precise systems require corroboration across signal families, shared assets plus synchronized behavior plus payment linkage, before a ring verdict, and maintain fast, humane appeal paths for linked accounts.
Go live in minutes. No sandbox required, no hidden fees.
A guide to trading card fraud: counterfeit slabs, reslabbing, trimmed cards, non-delivery and triangulation scams, and how to authenticate a graded slab.
A practical peer-to-peer marketplace safety guide: spot overpayment, fake-payment, and off-platform scams, and how identity verification protects both sides.
Persona, Jumio, and deepidv compared on fraud ring detection as new 2026 data shows 65.68% of linked fraud reusing forged documents across shared devices.