Rule coupon_hijack, from the product code

Leaked codes stealing your affiliates' customers

A coupon site scraps your checkout page and publishes a code. Every customer who was already referred by a real affiliate now hands credit to the code's owner at checkout. The affiliate loses the sale they brought you.

Rule 4th of 12Holds, never deletesEvidence in your queue

Fraud queue on demo data: coupon_hijack sits with its verdict, subject, reason and action, above the held commissions with amounts.

The fraud queue, running on demo data.

How the rule works

The exact mechanics, from the engine. No black box, no tuning required.

  1. 01Customer binding first

    Customers are bound to the affiliate who brought them, first touch, lifetime. A coupon can only steal credit the customer already had.

  2. 02Three customers in 7 days

    When one coupon takes credit for 3 or more customers bound to other affiliates inside a 7-day window, the rule fires and the coupon's owner is frozen.

  3. 03The freeze is reversible

    Freezing stops new credit while you review. Release it if the pattern was innocent, like a genuine influencer push, and every held commission returns to the pipeline.

The signals

  • 3+ overridden customers in 7 days
  • Coupon owner frozen pending review
Holds, never deletesA hold freezes the commission before payout. Nothing is lost while you decide.
Evidence attachedThe queue shows exactly what tripped, side by side with the sale.

What lands in your queue

When coupon hijack fires, this is what you see. Release or uphold is your call, not the engine's.

Fraud queue · coupon_hijack · demo dataMade-up numbers
Example held commissions after coupon hijack fired, on demo data
AffiliateWhat trippedCommissionStatus
Affiliate 42Coupon SPRING40 took credit for 3 bound customers in 7 days$358.00Held Owner frozen
heldWaits for youThe commission stays out of payouts until you decide.
releasedPaid normallyReal pattern after all. It returns to the pipeline.
upheldNot paidFraud confirmed. The clawback is journaled.

In the wild

Honey, in court since 2024

  • Case: In re PayPal Honey Browser Extension Litigation, N.D. Cal. 5:24-cv-09470, filed Dec 2024 after the MegaLag exposé. The initial class action was dismissed in Nov 2025 for lack of cognizable injury, with leave to amend; other suits were allowed to proceed. Source
  • Fallout: Rakuten Advertising expelled Honey from its network in Jan 2026. Google changed Chrome extension policy in Mar 2025 to bar extensions that claim affiliate commissions without giving a discount.
  • Scale: PayPal paid $4B for Honey in 2019; the extension had lost 4M+ users by May 2025. Source

Cases and figures verified against court records and named reports, . Vendor estimates are labelled as such.

How attackers try to beat it

Honey-style browser extensions auto-inject codes at checkout. The extension doesn't know which customers were already referred. Bound customers make the theft visible, and the third one triggers the freeze.

Every rule is one layer. The twelve overlap on purpose: beating one cleanly usually means walking into another.

Related rules

Rule thresholds checked against the code . Windows are rolling.

Coupon hijack questions

Can I change the threshold?

The thresholds ship fixed, tuned from the rule code and tested together. Tightening one in isolation breaks the overlap the twelve rules build as a set.

What does a hold cost me?

Nothing but time. A held commission is frozen, not deleted. If you release it, it flows to the next payout exactly as if the hold never happened.

Does this rule fire on my best affiliate?

Every rule is scoped to the commissions linked to what tripped it, weighted by conversions, and rate-limited on the click side. A rival can't aim it at your top earner.

This rule, on every sale,
before the payout.

Self-host for $99 once, or run it in the cloud free for 14 days.