Card testing is a billing problem before it's a fraud problem
Everyone treats card testing as fraud to be scored. By the time your fraud tool weighs in, the network has already charged you. Here's where the money actually leaks.
Most teams meet card testing through their fraud stack: a wave of small authorizations rolls in, the model flags them, and someone opens a dashboard. That framing is the problem. By the time a fraud score exists, the authorization has already left your server and reached the card network — and the network has already started charging you.
Card testing is a billing event first. The fraud is downstream.
Where the money leaks
The costs that matter aren’t chargebacks. They stack per attempt, before any transaction settles:
- Your gateway’s per-authorization fee — around $0.25 an attempt for a typical mid-market merchant, approved or declined.
- Visa APF — $0.0195 on every authorization, approved or declined. (Mastercard’s NABU is the same $0.0195 on Mastercard cards — an attempt runs on one network, so it’s one or the other, not both.)
- Visa Misuse of Authorization — $0.15 on approved authorizations never matched to a settlement or reversal, up from $0.09 in January 2025. Card testers never settle, so every approval they get bills it.
- Enumeration monitoring — Visa’s VAMP counts authorization attempts, declines included, against your standing with the network.
Price a 10,000-attempt run on Visa rails, with about 3.5% of attempts approving, and it’s $2,748 in fees before you count a single chargeback — $2,500 of it gateway fees, $195 APF, $53 Misuse of Authorization. A 100,000-attempt wave is roughly $27,000. None of it shows up where fraud teams look.
The authorization is the product the network sells you. Card testing makes you buy a hundred thousand units you never wanted.
Why scoring after the fact can’t fix it
A gateway-native tool — Radar and friends — scores the request after it has reached the network. That’s useful for deciding whether to capture, but the authorization fee is already incurred. You can block the charge and still pay for the attempt.
The only place to stop the bleeding is in front of the gateway:
internet ──▶ [ cardvera edge ] ──▶ your gateway
classify · decide only real traffic
in milliseconds no auth fees on blocked attempts
If the request never becomes an authorization, there’s no APF, no NABU, no misuse fee, no enumeration ratio to defend.
The mental model shift
Stop asking “is this transaction fraudulent?” and start asking “should this ever become an authorization at all?” The first question is a fraud problem you answer too late. The second is a billing problem you answer at the edge, in milliseconds, before the meter starts.
That shift — from scoring fraud to preventing the auth — is the entire reason Cardvera sits where it does.