One person, a hundred accounts, a hundred different fingerprints
Anti-detect browsers are commercial products with a single job: give every profile a borrowed identity. Hardware, fonts, GPU, timezone, screen — fabricated per profile, each profile behind its own proxy. To your systems, one operator on one laptop looks like a hundred unrelated people on a hundred unrelated devices.
You cannot see the person behind the profiles. You can see the tooling. Tracio catches the act of fingerprint spoofing itself and returns it as a score — which means it also catches products that have never appeared on anyone's list.
antidetect score, Pro plan and above
signal categories cross-checked for contradictions
device signals behind every visit
Built so that every profile looks like a different person
A normal browser has one fingerprint because it sits on one machine: one GPU, one set of fonts, one audio stack, one screen. An anti-detect browser cuts that link. You buy a subscription, create a profile, and the profile gets its own fabricated hardware, its own timezone, its own WebGL vendor, its own proxy. Profiles are saved, shared across a team, exported and resold like any other working asset.
Multi-accounting
Dozens or hundreds of accounts on one marketplace, exchange or ad platform, all operated from a single machine by a single person or team.
Ban evasion
A blocked account is back within minutes as a fresh profile: new fingerprint, new proxy, new browser identity, same operator.
Promo and bonus abuse
Sign-up bonuses, first-deposit offers, free trials and referral rewards farmed at scale. Budget meant for hundreds of new customers goes to one.
Affiliate and referral fraud
Self-referrals and manufactured conversions, where the affiliate and the newly acquired user are the same person on the same laptop.
Not everyone who runs one is committing fraud, and the product is built to make that distinction rather than flatten it.
The mechanism, not the brand list
A list of product names starts ageing the moment it is published. Tracio does not ask which product a session is running — it looks for what every one of them has to do to work.
By the spoofing mechanism
The signal looks for the act of spoofing rather than a product: values that contradict each other, APIs answering the way no physical device answers, a machine whose parts belong to different machines, and the injection hooks a patched engine leaves behind while it rewrites what a page is allowed to see. A build released next month, or a private in-house tool that was never sold to anyone, is caught the day it first shows up in your traffic.
As a score you can act on
The finding arrives as an antidetect score from 0 to 100, not as a brand name — so your rules key off how strong the evidence is instead of whether a vendor happened to be on someone's list. A high score next to an ordinary human behavioural profile is the signature case: a real person, working at human speed, on a fabricated device.
What the signal actually looks at
- Fingerprint-injection globals left in the page
- Injected CSS variables from a patched engine
- Specialised browser builds
- Fingerprint-substitution mechanisms
- Risky browser extensions
- GPU and renderer strings contradicting the reported hardware
- API answers no physical device produces
Extensions, after four trust checks
The add-ons installed in the visiting browser are part of the same picture: a fingerprint-substitution helper or a risky automation extension is a marker in its own right. Before a name is shown it passes four checks — a decoy probe that only a fabricated environment answers, a ceiling on how many detections one visit may report, repeat observation, and a registry match. A browser that “finds” everything betrays itself and the whole batch is discarded. What survives is listed by name and category in the visitor record, the Data API and webhooks, on Business plans and above. An empty list means nothing was seen, not that nothing is installed.
Privacy browsers are treated differently — deliberately
A hardened privacy browser is not a multi-accounting tool. It resists fingerprinting because that is the entire point of it, and the people using it are usually protecting themselves rather than running fifty seller accounts. It is reported like anything else, but it carries far less weight than a commercial anti-detect build. A privacy-conscious customer is still a customer, and treating them as a fraud ring is its own kind of mistake.
What the profile says, and what the machine is
An anti-detect profile rewrites what the browser reports. Independent measurements do not read the report — they look at what the hardware and the network actually do — so the two sides can be compared axis by axis. On Business plans and above the visit carries both: what was claimed, what was measured, and the axes that disagree.
Operating system
The OS the User-Agent names against the one the network layer reveals. A desktop presenting itself as an iPhone is the textbook case.
GPU
The reported video adapter against what the graphics stack actually delivers — a real adapter of that model has limits it cannot exceed or fall short of.
Screen
Claimed dimensions and pixel ratio against the geometry the page was really laid out in.
Network
The address the connection arrived from against the network its raw path actually leaves through.
Browser
The browser name and version against its real rendering and API surface, and against the TLS stack that carried the request.
A ladder, not a verdict
One confirmed contradiction adds 20 of 100 to the risk score, two add 70, further ones climb to a ceiling of 80 — below the weight of a caught bot. A spoofed visit is not declared a bot: the fact and the score are reported, and your rules decide.
When spoofing is proven, the visitor header shows the measured operating system next to the claimed one.
It shows up where you already look
In the visit record
Open a visitor and it is stated plainly: this session came through an anti-detect browser, with the score behind that call and the markers that produced it.
In analytics
Count and filter it like any other property. How much of last month's sign-up traffic arrived on spoofed fingerprints, which campaigns attracted it, which hours it clusters in.
In webhooks
Every event delivered to your backend carries the signal, so your own rules can react while the session is still open.
In the Data API
Query it after the fact — for one visitor, for a cohort, or for the month you are writing a chargeback report about. The same record carries the list of extensions and, when a spoof was proven, what was claimed and what was measured (Business and above).
Tracio hands you the evidence; your rules decide what it is worth. The same finding justifies step-up verification at sign-up on one site, a manual review queue for high-value orders on another, and nothing at all on a third — so the signal is delivered everywhere you can act on it, and the policy stays yours.
Wherever one account per person is the assumption
Marketplaces
Seller networks run from one desk, review rings, and buyer accounts that reappear the day after a ban.
iGaming and betting
Bonus farming, several seats at the same table, and accounts that come back after a self-exclusion request.
Fintech and crypto
Onboarding farms where dozens of customers share one operator, and payout schemes built on the same trick.
Promo campaigns
Sign-up credit, free trials and first-order discounts, where a handful of operators can absorb a budget meant for thousands.
Affiliate programs
Self-referrals and fabricated conversions that pass for organic growth until the tooling behind them becomes visible.
Frequently asked questions
See the tooling behind the accounts
The spoofing mechanism caught regardless of brand, an antidetect score from 0 to 100 on the Pro plan and above, and 300+ device signals behind it.