Fraud
Coupon extensions steal commissions. Here's how to catch them.
A customer was about to buy anyway. At checkout, a browser extension quietly drops the last-click cookie, and your affiliate program pays the wrong party. This is the most common affiliate fraud of the decade, and most programs never notice.
By the AffiliateTracking team · · 8 min
How the theft actually works
Most affiliate programs pay on last click. That single design choice is what extension fraud exploits. A customer browses your site because a newsletter, a search result, or a genuine affiliate sent them. When they open the checkout page, a coupon-finding extension wakes up, swaps in its own referral cookie, and reloads the page to test codes. From your tracker's point of view, the last click before purchase came from the extension's affiliate account.
The genuine influencer who drove the interest earns nothing. The extension, which contributed nothing but a code sweep, earns everything. Honey, Capital One Shopping, and a long tail of smaller extensions built entire businesses on this mechanic. When the practice hit the news in early 2025, the reaction from affiliate operators was not surprise. It was recognition.
This is not a grey area
Affiliate fraud through cookie manipulation has a body count. In the eBay case, the FBI investigated the company's top affiliate marketers for dropping cookies on users who never clicked, and people went to prison. The technique, cookie stuffing, is legally established fraud: courts treated it as wire fraud because payouts were obtained through false attribution claims. The modern extension playbook is the same crime with friendlier branding: instead of hidden iframes, it's a "coupon search" that incidentally overwrites attribution.
The four detection signals
You cannot stop extensions from existing. You can stop paying them. Four signals separate real influencers from code sweepers, and all four are computable from your own tracking data:
1. Near-100 percent coupon attach rates. Real affiliates send traffic that buys with and without codes. If one partner's conversions attach a discount code virtually every time, they are not sending customers. They are waiting at checkout.
2. New-customer mismatch. Extensions credit on sales to existing customers who were already buying. If a partner's "referred" customers are overwhelmingly returning accounts, the attribution is being manufactured at the last second.
3. Conversion timing compressed to checkout. Genuine affiliate traffic shows a click-to-purchase gap: people read, compare, come back. Extension fraud shows clicks seconds before payment. Distribution of time-to-conversion is the cleanest tell in your data.
4. Referral source concentration. Coupon-site affiliates and extension networks cluster: same domains, same code lists, signup bursts. When one junk signup appears, its siblings follow within weeks.
What to do about each
For attach-rate and timing anomalies, hold the commission for review instead of auto-approving. A hold costs nothing if the sale is real; you release it in one click. For source concentration, screen signups before approval: coupon-site applications are the highest-volume junk category in every open-enrollment program. For existing-customer mismatches, flag repeated customer-email overlap with partner accounts, which also catches the self-referral pattern.
The underlying discipline is simple: no commission should move without passing checks that compare the story the data tells with the story the attribution claims. When every payout decision is recorded in an append-only ledger, patterns like these surface in review instead of hiding in a payment history nobody audits.
The economics of ignoring it
Programs that ignore extension fraud do not just overpay. They underpay the affiliates who actually grow the business, and those affiliates leave. The most expensive outcome of attribution theft is not the stolen commission. It's the genuine promoter who quits because their numbers quietly collapsed while a code sweeper's numbers soared. Fraud review is retention work.
Where our rules fit
Our fraud engine runs twelve checks on every conversion, on every plan, and the coupon-extension patterns above are core targets: impossible timing, customer-email overlap, code-attach anomalies, duplicate-account families. Flagged commissions sit in a review queue with the evidence attached. You look, you decide, the ledger records it. That is the whole job: the money waits for the truth.