top of page

azakaw named an IDC Innovator in Middle East Regulatory Technology Providers 2026 Report

azakaw colored logo.png
Arrow 6.png

Multi-Accounting Fraud: What it is, why it costs you, and how to detect it

  • Writer: azakaw
    azakaw
  • Jul 24
  • 8 min read

One user. Ten accounts. Ten welcome bonuses, ten referral rewards, ten chances to evade your risk limits. Does it sound familiar? Yes, we're talking about multi-accounting fraud.


Multi-accounting is among the most common types of fraud within fintech, gaming, crypto, and online marketplaces. It initially seems harmless: a client registering twice.


In practice, it drains promotional budgets, distorts risk models, and creates very real exposure to money laundering.


This guide breaks down what multi-accounting fraud actually is. It covers how it works, why it costs your business more than you think, and how modern detection tools catch it before it scales.

Multi-Accounting Key Takeaways

  • Multi-accounting fraud occurs when one person or entity creates and controls multiple accounts to exploit bonuses, referral rewards, promotions, risk limits, or platform incentives.

  • Multi-accounting is particularly common in fintech, gaming, crypto, and online marketplaces.

  • The financial impact goes beyond bonus abuse: multiple accounts can also facilitate transaction layering, money laundering, chargebacks, and other forms of financial crime.

  • Fraudsters commonly hide connections between accounts using different emails and phone numbers, VPNs, proxies, device emulators, modified identity details, synthetic identities, and account farming.

  • Effective multi-account detection combines multiple signals and risk scoring rather than relying on a single signal.

  • Prevention should start during KYC onboarding and then continue through ongoing monitoring and re-verification.

  • Rule-based controls remain useful for known fraud patterns, while machine learning and behavioural analysis can identify new relationships and coordinated activity that predefined rules may miss.


What is multi-accounting?

Multi-accounting refers to one entity or individual creating multiple accounts on the same platform. The aim is almost always to gain some benefit that would not be allowed under a single account.


Multi-accounting vs. account takeover: what's the difference?

These two types of business fraud are easily confused but function quite differently.


Multi-accounting fraud involves the fraudster creating new accounts using their own or entirely fabricated identities. Account takeover (ATO) is when a fraudster steals access to an account that belongs to someone else.


Multi-accounting revolves around quantity and duplication. ATO is more about hijacking. 


Even though both will result in financial harm, they use very different detection methods because multi-accounting requires you to spot subtle links between accounts that appear completely unrelated.

Industries most affected by multi-accounting fraud

Multi-accounting pops up wherever accounts unlock actual value. It impacts fintech applications giving out referral bonuses. It hits online gaming platforms operating loyalty rewards. 


It impacts crypto exchanges handing out token airdrops. It impacts marketplaces with initial-user discounts. Any platform offering some form of repeatable incentive is a prime target for exploitation.


Scale with Confidence

Stay one step ahead with instant alerts. Our advanced AI-powered engine detects suspicious activities in real-time, helping you protect your business from potential risks with unparalleled accuracy.​



Why is multi-accounting a problem for your business?

Multi-accounting is a problem for businesses because it creates immediate financial losses, regulatory exposure, and prolonged harm to the trust your platform counts on.


Financial losses: bonus abuse, promo fraud, and chargebacks

Bonus abuse is perhaps the most obvious cost involved here.


A fraudster opening 50 accounts to claim a $20 sign-up bonus will take home $1,000 after just a few hours' effort if they're successful. Referral plans are exploited in much the same way, with fraudsters also referring accounts they manage.


Crypto airdrops serve as a prime example. When Arbitrum carried out its ARB token airdrop back in March 2023, Nansen teamed up with the Arbitrum Foundation to scan out 2.3 million addresses.


They then ruled out roughly 135,000 addresses that had been identified as Sybil accounts: a single entity managing numerous wallets to claim several allocations.


Advanced Liveness Detection

Use real-time liveness tests to authenticate identities and prevent ID fraud. azakaw provides immediate verification, distinguishing legitimate users from fraudsters to safeguard your business.



Regulatory exposure and AML risk

Multi-accounting is directly linked to AML risk in highly regulated sectors.


If there's one bad actor managing dozens of accounts, they'll be able to layer transactions over them, making it much more difficult to view the entire pattern of their activity. This is a well-documented money laundering typology: splitting funds amongst numerous small accounts to remain below reporting thresholds.


If you're on a KYC-regulated platform and don't notice multi-accounting, then your Customer Due Diligence process didn't catch those duplicate identities. To regulators, this will be seen as a weakness in your controls rather than some minor technical issue.



Reputational damage and platform integrity

Bonus abuse and multi-accounting hurt your honest users. When scammers empty promotional funds, platforms respond by decreasing bonus value or imposing even tighter restrictions on all users.


Your genuine customers are left with a worse product since just a few bad actors played the system first.

How does multi-accounting fraud work?

Scammers have developed consistent methods for creating and operating numerous accounts without triggering the most basic fraud checks. Understanding these techniques is really the very first step towards catching them.


Common techniques used by multi-accounters

  • Utilising a different email address and phone number for each account, often created with disposable email services.

  • Changing IP addresses using VPNs, proxies, or residential proxy networks to evade IP-based flags

  • Employing device emulators or virtual machines to mimic several unique devices out of one actual physical location

  • Making only slightly altered personal details - adding a middle name here, changing a birthdate by just one day - to evade being detected as an exact duplicate

  • Recruiting additional individuals to open accounts for them, a practice referred to as account farming


How fraudsters bypass standard KYC checks

Standard KYC checks compare provided information against a database looking for an exact match. Scammers take advantage of this fact by introducing a bit of variation that defeats exact matching. 


Combining a genuine ID number with a fully fabricated name produces a synthetic identity that could easily fool a simple document check whilst presenting a completely fictional customer profile. Weak KYC deduplication is the primary reason multi-accounting groups succeed on such a large scale.


Read also:


How to detect multi-accounting

Identification will be far more effective if it uses multiple signals. There isn't a single method that can catch every trick, so layered identification has become the typical approach today.

Detection method

What it catches

Limitation

Device

fingerprinting

Same physical device used across accounts

Emulators can spoof device signals

IP

clustering

Accounts sharing network origin

VPNs and proxies mask true IP

Behavioral

biometrics

Typing rhythm, mouse movement matches

Requires baseline data to compare against

Identity graph /

KYC dedupe

Shared or near-matching identity fields

Needs fuzzy matching to catch small variations

Velocity checks

Rapid signup or transaction bursts

Legitimate high-volume users may trigger false positives

Anti-Multi-Accounting System

Benefit from the latest technology with an AI-powered engine that uses multiple signals for identity verification: real-time liveness tests and document verification. azakaw protects your business from fraudsters.



Device fingerprinting and IP analysis

Device fingerprinting gathers various technical signals coming from your user's device: screen resolution, browser configuration, installed fonts, and hardware identifiers, creating a truly unique profile. 


If the same fingerprint appears across accounts supposed to belong to completely different people, that's a strong sign of multi-accounting activity.

An additional layer comes from IP clustering, highlighting cases where numerous accounts originate from the same network or a very limited IP range.


Behavioural biometrics and usage patterns

Behavioural biometrics analyse how a person interacts with an application: their typing speed, scroll patterns, and even the angle they hold their phone at. These patterns are quite difficult to fake consistently across accounts.


When the same behavioural signature appears across accounts set up under different names, it will strongly suggest that one person is behind them all.


Identity graph and KYC deduplication

An identity graph represents relationships amongst all your users' data points, such as common addresses, telephone numbers, payment methods and document numbers.


KYC deduplication relies on this graph, along with fuzzy-matching algorithms, to identify very similar identities that exact-match systems might overlook. This is the key defence mechanism against synthetic identity fraud, which involves creating multiple accounts.


Velocity checks and risk scoring

Velocity checks highlight any unusual speed: numerous sign-ups originating from a single device within a few minutes, or a large number of completely new accounts initiating their first transaction on the same day.


When combined into a risk score, velocity information helps determine which accounts must be manually reviewed versus automatically approved, based on their priority level.

How to prevent multi-accounting at scale

Detection identifies fraud only after it has begun. Prevention prevents it from ever taking hold right from the start. A really effective programme combines elements of both detection and prevention strategies.


KYC at onboarding

If you don't know what KYC means, we explain: identify customer identity. The earlier you can detect duplication, the less expensive it will be to stop it altogether.


Performing a robust KYC procedure right at the beginning of the sign-up process ( document verification, biometric 'liveness' tests, and identity graph screenings) stops a significant proportion of multi-accounting attempts before even a single fraudulent account has been activated.


Reduce Multi-Account Fraud

azakaw’s KYC solution allows you to create customised onboarding flows and verify individual customers or legal entities with ease. Reduce fraud risk with the best AI system in the market.



Continuous monitoring and re-verification

Fraud doesn't simply cease post-sign-up. Continuous monitoring tracks activity once an account is live, flagging patterns that may indicate a link to other accounts on your platform.


Periodic re-verification, especially around high-value activities such as claiming bonuses or making large withdrawals, bridges the gap left by just carrying out a single check initially.


Automated fraud rules vs. machine learning models

Rule-based systems can quickly identify familiar patterns: the same device, IP address, or payment card details being used. However, the problem with relying on predefined rules is that they will only catch what they've been programmed to see.


On the other hand, machine learning models learn from historical fraud cases to identify new multi-accounting patterns that predefined rules may miss.


A recent example is the 2024 LayerZero airdrop. The protocol identified nearly 800,000 suspected Sybil addresses among approximately six million wallets using a combination of on-chain analysis and a self-reporting mechanism.


Frequently asked questions


Is multi-accounting illegal?

Creating multiple accounts to exploit bonuses generally contravenes a platform's terms of use, but isn't necessarily a criminal offence.


However, if it's carried out using stolen identities, artificially generated documentation, or money-laundering techniques, it could be considered a serious crime under various anti-fraud laws.


How do platforms detect multiple accounts?

Platforms will combine various methods, such as device fingerprinting, IP clustering, behavioural biometrics, identity graph analysis, and velocity checks. No single indicator will ever be conclusive enough on its own.


By layering these methods on top of each other, you catch not just very obvious multi-accounting attempts but also more subtle ones that try to alter details across accounts.


Can VPNs and emulators bypass multi-account detection?

They will avoid some basic checks based solely on your IP address or device ID. Nevertheless, today's detection systems combine behavioural biometrics, identity graph matching, and velocity analysis along with device and IP signals.


A fraudster may hide one signal but hardly ever conceals all of them persistently across each account under their control.


Conclusion

Multi-accounting fraud costs platforms real money through bonus abuse, distorts risk models, and creates genuine AML exposure when it's used to layer illicit funds across accounts.


The Arbitrum and LayerZero airdrop cases provide a glimpse into the size of this problem, seeing hundreds of thousands of duplicate identities seeking rewards meant for genuine users. This dynamic plays out every day on fintech, gaming, and marketplace platforms, albeit at a smaller, much less publicised level.


Detection really works better in layers: device fingerprinting, IP clustering, behavioural biometrics, identity graph deduplication, and velocity checks, backed by robust customer due diligence at sign-up and ongoing monitoring afterwards.


azakaw - The Best Fraud Detector

KYC and behavioural fraud layer is built to catch multi-accounting before it scales by combining identity deduplication, device and IP analysis, and behavioural signals into a single detection workflow for fintech, gaming, crypto, and marketplace platforms.



Multi-Accounting Fraud Video Summary


Related articles

 
 
bottom of page