SardineCon SF/2026

Learn More
Device & behavioral4 min de lectura

¿Qué es CAPTCHA?

Suscribite al newsletter

A CAPTCHA is a challenge placed at signup, login, or checkout that is meant to be easy for a human and hard for a bot. It is a first line of defense against automated fraud like credential stuffing and card testing, though modern attackers have many ways around it.

What is a CAPTCHA?

CAPTCHA stands for a test to tell computers and humans apart. In practice it is the puzzle at a sensitive step: type the distorted letters, pick the images with a bus, or just tick a box that quietly watches how you move. The goal is to let real people through while blocking the automated scripts that hammer signups, logins, and checkouts.

Newer CAPTCHAs do less asking and more watching. Instead of a visible puzzle, they score signals like mouse movement, timing, and browser characteristics, and only show a challenge when the score looks robotic. That shift matters because most automated fraud is about volume, and anything that slows the machine down changes the economics of the attack.

For a fraud team, a CAPTCHA is one control in a layered defense. It sits in front of the actions bots love to automate and buys time and signal, but it was never designed to be the only thing standing between an attacker and an account.

Life with and without a CAPTCHA

A CAPTCHA does not make automation impossible; it makes it slower and more expensive, which is often enough to push casual attacks elsewhere.

What changes

Without a CAPTCHA

With a CAPTCHA

Attack speed

Thousands of attempts per minute.

Each attempt needs to clear a challenge.

Cost to the attacker

Near zero per attempt.

Compute, solver fees, or human solvers.

Signal to defenders

Little friction data.

Behavior and challenge scores to act on.

Good-user impact

None, but neither is protection.

Some friction, worst for a small share of users.

What it looks like in practice

A retailer sees a flood of login attempts using email and password pairs leaked in an old breach. It adds an invisible CAPTCHA to the login page. The volume of successful automated logins drops sharply overnight, and the traffic that remains starts failing the behavioral score.

Within days the attacker adapts, routing attempts through a CAPTCHA-solving service and a network of residential proxies. The raw block rate falls, but the solver adds cost and latency, and the extra step gives the fraud team a fresh signal to combine with velocity and device checks, which catch the slower attack the CAPTCHA alone would have missed.

Why a CAPTCHA is a speed bump, not a wall

A CAPTCHA earns its place by raising the cost of automation. It pushes low-effort bots off to easier targets and generates behavioral signal a team can fold into risk scoring. On a login or signup page facing credential stuffing or fake-account creation, that friction can cut automated success rates dramatically at little cost to real users.

The catch is that CAPTCHAs are routinely beaten. Cheap solving services use both software and low-paid human solvers, and adversary-in-the-middle kits relay challenges to the real user. A CAPTCHA also adds friction that hurts a minority of legitimate users, especially those using assistive technology. So treat it as one layer that works best combined with device intelligence, velocity limits, and behavioral analytics.

What to watch in the data

  • Solve-time patterns. Challenges cleared far faster or more uniformly than humans manage suggest an automated or outsourced solver.
  • Pass then fail downstream. Traffic that clears the CAPTCHA but fails velocity or device checks points to bots that bought their way past it.
  • Proxy and datacenter IPs. A spike in challenges from rotating residential or datacenter addresses is a sign of an automated campaign.
  • Reused sessions. Many accounts sharing a single solved token or session hint at replay after a paid solve.
  • Friction on good users. Rising challenge rates for known-good customers can mean the CAPTCHA is miscalibrated and costing you conversions.

Quick questions

Do CAPTCHAs actually stop bots?

They stop simple, cheap automation and slow down the rest, but they do not stop a determined attacker. Solving services and adversary-in-the-middle relays defeat them, so a CAPTCHA should be one layer among several rather than the whole defense.

What is an invisible CAPTCHA?

It is a version that scores behavior in the background, such as mouse movement and timing, and only shows a visible puzzle when the traffic looks suspicious. It reduces friction for real users while still challenging likely bots.

How do fraudsters get past a CAPTCHA?

Common routes are automated solving software, human solving farms that clear challenges for a small fee, and real-time relay attacks that pass the puzzle to the genuine victim. Residential proxies help them avoid IP-based blocks at the same time.

Do CAPTCHAs hurt conversion?

They can. Every added challenge risks losing some genuine users, and they create real accessibility problems for people using screen readers or with certain disabilities. Teams weigh that friction against the fraud a CAPTCHA prevents and tune it accordingly.

Where should a CAPTCHA sit?

On the actions bots most want to automate: account signup, login, password reset, and sometimes checkout. Placing it only where risk is high keeps friction off the pages where it would cost sales for no benefit.

Qué saber junto con CAPTCHA

Reporte

Informe de Fraude y ALD 2026

Olvídate de las predicciones. Este informe desglosa a qué se enfrentan realmente los equipos de fraude y ALD, y cómo responder.

Descargar reporte