<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cardvera — Notes from the edge</title><description>Card-testing intelligence, fraud patterns, and engineering notes from the Cardvera team.</description><link>https://cardvera.io/</link><item><title>CAPTCHA doesn&apos;t stop bots, it taxes your real customers</title><link>https://cardvera.io/blog/captcha-taxes-your-real-customers/</link><guid isPermaLink="true">https://cardvera.io/blog/captcha-taxes-your-real-customers/</guid><description>CAPTCHA is the reflex when automated abuse shows up. But it charges the wrong party: every real customer pays the friction continuously, while the attacker it targets pays almost nothing. The fix is a tax the bot pays and the customer never sees.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Card testing is a billing problem before it&apos;s a fraud problem</title><link>https://cardvera.io/blog/why-card-testing-is-a-billing-problem/</link><guid isPermaLink="true">https://cardvera.io/blog/why-card-testing-is-a-billing-problem/</guid><description>Everyone treats card testing as fraud to be scored. By the time your fraud tool weighs in, the network has already charged you. Here&apos;s where the money actually leaks.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Velocity detection alone is a trap</title><link>https://cardvera.io/blog/velocity-detection-alone-is-a-trap/</link><guid isPermaLink="true">https://cardvera.io/blog/velocity-detection-alone-is-a-trap/</guid><description>Rate limits feel like the answer to card testing. But every single-dimension defense names the exact thing the attacker should change next. The trap isn&apos;t that velocity is wrong — it&apos;s that it&apos;s alone.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>Your payment gateway wasn&apos;t built to stop card testing</title><link>https://cardvera.io/blog/gateway-card-testing/</link><guid isPermaLink="true">https://cardvera.io/blog/gateway-card-testing/</guid><description>Merchants treat the gateway and its velocity rules as the line of defense against card testing. But the gateway is the meter the attacker is feeding. By the time traffic reaches it, the authorization is already being requested, and the network is already counting. Here&apos;s why the only place to stop the burst is in front of it.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate></item></channel></rss>