Skip to content
Anti-Detect Browsers

One person, a hundred accounts, a hundred different fingerprints

Anti-detect browsers are commercial products with a single job: give every profile a borrowed identity. Hardware, fonts, GPU, timezone, screen — fabricated per profile, each profile behind its own proxy. To your systems, one operator on one laptop looks like a hundred unrelated people on a hundred unrelated devices.

You cannot see the person behind the profiles. You can see the tooling. Tracio catches the act of fingerprint spoofing itself and returns it as a score — which means it also catches products that have never appeared on anyone's list.

0–100

antidetect score, Pro plan and above

15

signal categories cross-checked for contradictions

300+

device signals behind every visit

The tool

Built so that every profile looks like a different person

A normal browser has one fingerprint because it sits on one machine: one GPU, one set of fonts, one audio stack, one screen. An anti-detect browser cuts that link. You buy a subscription, create a profile, and the profile gets its own fabricated hardware, its own timezone, its own WebGL vendor, its own proxy. Profiles are saved, shared across a team, exported and resold like any other working asset.

Multi-accounting

Dozens or hundreds of accounts on one marketplace, exchange or ad platform, all operated from a single machine by a single person or team.

Ban evasion

A blocked account is back within minutes as a fresh profile: new fingerprint, new proxy, new browser identity, same operator.

Promo and bonus abuse

Sign-up bonuses, first-deposit offers, free trials and referral rewards farmed at scale. Budget meant for hundreds of new customers goes to one.

Affiliate and referral fraud

Self-referrals and manufactured conversions, where the affiliate and the newly acquired user are the same person on the same laptop.

Not everyone who runs one is committing fraud, and the product is built to make that distinction rather than flatten it.

Detection

The mechanism, not the brand list

A list of product names starts ageing the moment it is published. Tracio does not ask which product a session is running — it looks for what every one of them has to do to work.

Level 1

By the spoofing mechanism

The signal looks for the act of spoofing rather than a product: values that contradict each other, APIs answering the way no physical device answers, a machine whose parts belong to different machines, and the injection hooks a patched engine leaves behind while it rewrites what a page is allowed to see. A build released next month, or a private in-house tool that was never sold to anyone, is caught the day it first shows up in your traffic.

Level 2

As a score you can act on

The finding arrives as an antidetect score from 0 to 100, not as a brand name — so your rules key off how strong the evidence is instead of whether a vendor happened to be on someone's list. A high score next to an ordinary human behavioural profile is the signature case: a real person, working at human speed, on a fabricated device.

What the signal actually looks at

  • Fingerprint-injection globals left in the page
  • Injected CSS variables from a patched engine
  • Specialised browser builds
  • Fingerprint-substitution mechanisms
  • Risky browser extensions
  • GPU and renderer strings contradicting the reported hardware
  • API answers no physical device produces

Extensions, after four trust checks

The add-ons installed in the visiting browser are part of the same picture: a fingerprint-substitution helper or a risky automation extension is a marker in its own right. Before a name is shown it passes four checks — a decoy probe that only a fabricated environment answers, a ceiling on how many detections one visit may report, repeat observation, and a registry match. A browser that “finds” everything betrays itself and the whole batch is discarded. What survives is listed by name and category in the visitor record, the Data API and webhooks, on Business plans and above. An empty list means nothing was seen, not that nothing is installed.

Privacy browsers are treated differently — deliberately

A hardened privacy browser is not a multi-accounting tool. It resists fingerprinting because that is the entire point of it, and the people using it are usually protecting themselves rather than running fifty seller accounts. It is reported like anything else, but it carries far less weight than a commercial anti-detect build. A privacy-conscious customer is still a customer, and treating them as a fraud ring is its own kind of mistake.

Claimed against measured

What the profile says, and what the machine is

An anti-detect profile rewrites what the browser reports. Independent measurements do not read the report — they look at what the hardware and the network actually do — so the two sides can be compared axis by axis. On Business plans and above the visit carries both: what was claimed, what was measured, and the axes that disagree.

Operating system

The OS the User-Agent names against the one the network layer reveals. A desktop presenting itself as an iPhone is the textbook case.

GPU

The reported video adapter against what the graphics stack actually delivers — a real adapter of that model has limits it cannot exceed or fall short of.

Screen

Claimed dimensions and pixel ratio against the geometry the page was really laid out in.

Network

The address the connection arrived from against the network its raw path actually leaves through.

Browser

The browser name and version against its real rendering and API surface, and against the TLS stack that carried the request.

A ladder, not a verdict

One confirmed contradiction adds 20 of 100 to the risk score, two add 70, further ones climb to a ceiling of 80 — below the weight of a caught bot. A spoofed visit is not declared a bot: the fact and the score are reported, and your rules decide.

When spoofing is proven, the visitor header shows the measured operating system next to the claimed one.

What you get

It shows up where you already look

In the visit record

Open a visitor and it is stated plainly: this session came through an anti-detect browser, with the score behind that call and the markers that produced it.

In analytics

Count and filter it like any other property. How much of last month's sign-up traffic arrived on spoofed fingerprints, which campaigns attracted it, which hours it clusters in.

In webhooks

Every event delivered to your backend carries the signal, so your own rules can react while the session is still open.

In the Data API

Query it after the fact — for one visitor, for a cohort, or for the month you are writing a chargeback report about. The same record carries the list of extensions and, when a spoof was proven, what was claimed and what was measured (Business and above).

Tracio hands you the evidence; your rules decide what it is worth. The same finding justifies step-up verification at sign-up on one site, a manual review queue for high-value orders on another, and nothing at all on a third — so the signal is delivered everywhere you can act on it, and the policy stays yours.

Who this matters to

Wherever one account per person is the assumption

Marketplaces

Seller networks run from one desk, review rings, and buyer accounts that reappear the day after a ban.

iGaming and betting

Bonus farming, several seats at the same table, and accounts that come back after a self-exclusion request.

Fintech and crypto

Onboarding farms where dozens of customers share one operator, and payout schemes built on the same trick.

Promo campaigns

Sign-up credit, free trials and first-order discounts, where a handful of operators can absorb a budget meant for thousands.

Affiliate programs

Self-referrals and fabricated conversions that pass for organic growth until the tooling behind them becomes visible.

FAQ

Frequently asked questions

See the tooling behind the accounts

The spoofing mechanism caught regardless of brand, an antidetect score from 0 to 100 on the Pro plan and above, and 300+ device signals behind it.