How to Block Shopify Bot Attacks and Fake Abandoned Carts

How to Block Shopify Bot Attacks and Fake Abandoned Carts

Introduction

You open your Shopify admin, and something is wrong. Your abandoned cart count has exploded overnight — thousands of carts, all containing the same product, created minutes apart. Your abandoned cart email flows are firing at scale. Your inventory reservation numbers look completely off. Your analytics are polluted with sessions that don't look human.

You're under a bot attack.

This isn't just an annoyance. Bot-generated abandoned carts cause real, measurable damage: skewed analytics, wasted email sends, potential inventory lockup, degraded store performance, and — if the bots are sophisticated — actual fraud downstream. This guide walks through identifying the attack, stopping it immediately, cleaning up the damage, and hardening your store against future attacks.


What Bots Are Actually Doing

Understanding the bot's goal helps you choose the right countermeasures. The most common bot attack patterns that generate fake abandoned carts are:

1. Inventory Denial (Scalper Bots): Bots add high-demand items to cart to reserve inventory, preventing real customers from purchasing. Common during product drops, limited releases, and restocks.

2. Competitive Intelligence Scraping Bots systematically add products to cart to trigger pricing or stock-level responses — harvesting data about your inventory and pricing behavior.

3. Carding / Payment Testing Bots create carts and proceed to checkout to test stolen credit card numbers at scale. The abandoned carts are a byproduct of failed payment attempts.

4. Email Harvesting for Spam: If your abandoned cart flow requests an email before checkout completes, bots may be submitting fake or harvested email addresses to generate outbound email traffic from your domain — damaging your sender reputation.

5. DDoS via Cart Creation: High-volume cart creation requests are used to consume server resources and slow your storefront for real customers.


Step 1 — Confirm It's a Bot Attack

Before taking action, verify the pattern is bot-driven rather than a legitimate traffic spike.

Signs it's bots, not humans:

  • Hundreds or thousands of carts created within minutes or hours
  • All or most carts contain the exact same product/variant
  • Cart creation times are evenly spaced (e.g., every 30 seconds) — humans are irregular
  • Sessions originate from a narrow range of IP addresses or the same geographic location
  • Sessions show zero browsing behavior — cart created immediately on session start, no page views
  • Customer emails in abandoned carts follow a pattern (random strings, same domain, disposable addresses)
  • No corresponding ad traffic or referral source that would explain the spike

How to check in Shopify:

  1. Go to Analytics → Reports → Abandoned checkouts
  2. Export the data and look for patterns in email addresses, IP addresses (if available), and timestamps
  3. Go to Analytics → Sessions — look for sudden traffic spikes with high bounce rates and near-zero session duration

Use external tools:

  • Check your server logs (via Shopify's Log feature or a connected analytics platform) for IP clustering
  • Run suspicious IPs through ipinfo.io or AbuseIPDB to identify known bot/proxy IPs

Step 2 — Immediate Containment

Take these actions immediately to stop the bleeding while you implement permanent fixes.


🛑 Action A — Enable Shopify's Built-In Bot Protection

Shopify has native bot protection built into the platform:

  1. Go to Shopify Admin → Online Store → Preferences
  2. Scroll to Spam protection
  3. Ensure "Filter spam from online store contact forms" is enabled
  4. For checkout-level protection, Shopify automatically applies fraud analysis on all orders — ensure you haven't disabled this

Shopify also uses Cloudflare at the infrastructure level, which provides baseline DDoS and bot mitigation for all stores. However, this doesn't block all sophisticated bots.


🛑 Action B — Add Google reCAPTCHA or hCaptcha to Your Storefront

Bots that create carts typically interact with your Add to Cart button or the cart API endpoint directly. Adding a CAPTCHA challenge breaks automated scripts.

Options:

  • Shopify's native bot protection on checkout — enabled by default, adds invisible reCAPTCHA to checkout
  • Third-party CAPTCHA apps — add visible or invisible challenges to the Add to Cart button (see Step 6 for app recommendations)

Note: Shopify does not natively allow adding CAPTCHA to the Add to Cart button without a third-party app or custom theme code. The checkout-level protection is built in.


🛑 Action C — Temporarily Password-Protect Your Store or Specific Products

If the attack is severe and ongoing, a temporary password gives you breathing room:

  1. Go to Online Store → Preferences → Password protection
  2. Enable the password and share it only through your legitimate marketing channels
  3. This immediately stops all automated cart creation

Less disruptive alternative — restrict access to the affected product:

  1. Go to the targeted product
  2. Set it to Draft status temporarily
  3. Remove it from all sales channels
  4. This makes the product inaccessible to bots while keeping the rest of your store open

🛑 Action D — Block Known Bot IP Ranges at the Network Level

If you have Cloudflare (either through Shopify or your own account) or another WAF (Web Application Firewall):

Cloudflare (free tier and above):

  1. Log in to Cloudflare
  2. Go to Security → WAF → Custom Rules
  3. Create a rule to block or challenge requests from known bot IP ranges
  4. Enable Bot Fight Mode (free) or Super Bot Fight Mode (Pro+)
  5. Set the Security Level to "High" temporarily

Block specific IPs in Cloudflare:


Rule: (ip.src in {1.2.3.4 1.2.3.5 1.2.3.0/24})
Action: Block

If you don't have Cloudflare:

  • Contact Shopify Support with the attacking IP ranges — they can apply network-level blocks at the infrastructure level

Step 3 — Identify and Block the Attack Vector

Bots reach your cart through one of two paths. Identify which one and block it at the source.


Vector A — Storefront UI (Browser-Based Bots)

The bot is simulating a browser, clicking "Add to Cart" as a human would. These are harder to block because they pass basic checks.

Detection: Sessions appear in your analytics with a browser user-agent but have zero dwell time and robotic timing patterns.

Fix:

  • Implement behavioral analysis via a bot protection app (see Step 6)
  • Add invisible honeypot fields to your cart form — real browsers ignore hidden fields, bots fill them in
  • Implement rate limiting on Add to Cart actions per IP or session

Vector B — Direct API Calls (Headless Bots)

The bot is calling Shopify's Cart API (/cart/add.js) directly without loading a browser at all — bypassing your storefront entirely.

Detection: No corresponding page view sessions, extremely high request volume, no JavaScript execution (no client-side events fire).

Fix — Rate Limit the Cart API:

If you have Cloudflare:


Rule: (http.request.uri.path eq "/cart/add.js" and cf.threat_score gt 10)
Action: Challenge

Or add a rate limit rule:


Path: /cart/add*
Method: POST
Threshold: 10 requests per 60 seconds per IP
Action: Block for 1 hour

Fix — Require a Valid Session Token:

Implement a server-side token check before allowing cart additions. This requires custom development but effectively blocks headless API bots that don't maintain a full browser session.


Step 4 — Clean Up the Fraudulent Cart Data

Once the attack is contained, clean up the polluted data.


Clean Up Abandoned Checkout Records

Shopify does not provide a bulk-delete tool for abandoned checkouts in the admin UI. Your options:

Option A — Use the Shopify Admin GraphQL API:


# Query abandoned checkouts to identify fraudulent ones
{
  abandonedCheckouts(first: 250, query: "created_at:>2026-09-28") {
    edges {
      node {
        id
        email
        createdAt
        lineItems(first: 5) {
          edges {
            node {
              title
              quantity
            }
          }
        }
      }
    }
  }
}

Use a script or tool (Matrixify, custom Node.js script) to identify and delete fraudulent abandoned checkout records in bulk.

Option B — Use Matrixify (you have it installed):

  1. Open Matrixify from your Shopify apps
  2. Export Abandoned Checkouts with a date filter covering the attack period
  3. In the export, identify fraudulent entries (same product, bot email patterns)
  4. Use Matrixify's bulk delete functionality to remove them

Option C — Wait for Natural Expiry: Shopify automatically deletes abandoned checkout records after 3 months. If the attack data isn't critical to clean immediately and isn't triggering emails, this is the lowest-effort option.


Stop Abandoned Cart Emails from Firing at Bot Addresses

This is urgent — sending thousands of emails to bot/fake addresses destroys your email sender reputation.

Immediate fix:

  1. Go to Marketing → Automations (or your email marketing app)
  2. Pause all abandoned cart email flows temporarily
  3. If you're using Shopify Email or a third-party app, check for a send rate or daily limit setting and reduce it drastically
  4. Add email validation filters to your abandoned cart flow:
    • Filter out emails from known disposable domains (mailinator.com, guerrillamail.com, etc.)
    • Filter out emails with obvious bot patterns (random strings of characters)
    • Only send to addresses that have a name associated with the checkout

In Shopify Flow — add a condition before sending:


Trigger: Checkout abandoned
Condition: Customer email does not contain "mailinator"
Condition: Customer email does not contain "guerrillamail"
Condition: Checkout has billing address (bots often skip this)
Then: Send abandoned cart email

Restore Inventory Accuracy

If the bots were reserving inventory through incomplete checkouts, your inventory numbers may be inflated (showing items as reserved that aren't really sold).

  1. Go to Products → [Affected Product] → Inventory
  2. Compare committed inventory (reserved in checkouts) against real order counts
  3. If committed inventory is unrealistically high, the bot checkouts are holding reservations
  4. Shopify releases checkout inventory reservations after ~10 minutes of inactivity for guest checkouts — if the attack has stopped, this should self-correct within hours
  5. If you need to force-release inventory, contact Shopify Support with the details

Step 5 — Harden Against Future Attacks

Now that the immediate crisis is resolved, implement permanent defenses.


Defense 1 — Implement a Queue System for High-Demand Drops

If the bots are targeting limited product releases:

  • Use a virtual waiting room app (e.g., Crowd Control, Queue-it, or Shopify's built-in product drop features)
  • Enable one-per-customer limits on high-demand products
  • Use customer account requirements — require login before adding to cart (bots struggle with authenticated sessions)

Defense 2 — Require Customer Accounts for Checkout

Bots operate best as guests. Requiring an account to checkout adds significant friction:

  1. Go to Settings → Customer accounts
  2. Set accounts to Required for checkout
  3. This forces bots to create and verify accounts — a step most bot scripts aren't built to handle

Trade-off: This reduces conversion rates for new customers. Consider requiring accounts only during attack windows or for specific product collections.


Defense 3 — Implement Checkout.liquid Customizations (Plus Only)

Shopify Plus merchants can customize checkout.liquid to add additional bot-prevention logic:

  • Add invisible honeypot fields to checkout forms
  • Inject custom JavaScript to detect headless browsers (no window, no canvas fingerprint, etc.)
  • Add behavioral scoring that delays or challenges sessions with robotic timing

Defense 4 — Set Up Real-Time Monitoring and Alerts

Create a Shopify Flow workflow that alerts you when bot-like patterns emerge:


Trigger: Checkout created
Condition: Number of checkouts with same variant in last 60 minutes > 50
Action: Send email alert to store owner
Action: Add tag "bot-suspect" to checkout

Also set up monitoring in your analytics platform:

  • Alert when cart creation rate exceeds your normal baseline by 300%
  • Alert when a single product appears in >50% of new carts in any 30-minute window

Defense 5 — Use a Dedicated Bot Protection App

For ongoing protection, a dedicated security app is the most robust solution. Look for apps that offer:

  • Behavioral fingerprinting — identifies bots by how they interact with the page, not just IP
  • Device fingerprinting — ties sessions to devices, not just IPs (which bots rotate)
  • Rate limiting on cart actions — per IP, per device, per session
  • Known bot IP blocklisting — auto-updated databases of malicious IPs
  • Headless browser detection — flags Puppeteer, Selenium, and other automation tools

When evaluating bot protection apps for the Shopify App Store, look for:

  • Reputational signals: High review count, "Built for Shopify" badge, active developer
  • Shopify-specific integration: Hooks into the Cart API and checkout natively
  • Transparent pricing: Flat rate preferred over per-request pricing at high volume
  • Dashboard and reporting: You need to see what's being blocked and why

Search the Shopify App Store for: "bot protection", "fraud prevention", or "CAPTCHA" to find currently rated options.


Step 7 — Report the Attack

Report to Shopify:

  • Contact Shopify Support with the attack details: IP ranges, timestamps, affected products, and volume
  • Shopify's Trust & Safety team can apply network-level mitigations and document the attack pattern

Report malicious IPs:

  • Submit attacking IPs to AbuseIPDB — this helps the broader community block them
  • If you have Cloudflare, their threat intelligence automatically learns from your reported traffic

If carding is suspected:

  • Contact your payment provider immediately
  • Shopify Payments has a dedicated fraud team — flag the incident through your admin's Payments section
  • Consider temporarily enabling 3D Secure on all transactions during the attack window

Post-Attack Audit Checklist

After the attack is resolved, audit what happened and what it cost:

  • Total number of fake abandoned checkouts created
  • Number of abandoned cart emails sent to bot addresses
  • Email sender reputation impact (check deliverability scores in your email platform)
  • Inventory accuracy confirmed and corrected
  • Analytics data flagged/segmented to exclude the attack period
  • Bot protection measures implemented and tested
  • Monitoring/alerting in place for future attacks
  • Shopify Support ticket filed with full attack details
Back to blog

Leave a comment