The first consumer scale agent has arrived

Read more
Case Study

How Zilch Stopped 99.4% of Credential Stuffing Attacks and Freed Up Security Team

Zilch partnered with Arkose Labs to stop credential stuffing. Here's how we handled 37,000 automated attacks in just 4 hours - and freed the Zilch security team from overnight escalations.

37K

automated attack attempts handled in 4 hours

99.4%

of credential stuffing attempts stopped immediately

97%

of traffic flows through transparent mode

THE CHALLENGES

  • Persistent credential stuffing and fake account creation threatened Zilch's login (ATO) and registration (NAO) flows as rapid expansion drove sign-up
  • Attackers used advanced spoofing, including impossible device configurations, that manual review couldn't catch in time
  • Reactive, round-the-clock IP and country blocking consumed security team resources
  • No automated way to distinguish legitimate users from sophisticated bots operating across distributed locations

THE ARKOSE TITAN SOLUTION

  • Deployed Arkose Titan to protect Zilch's auth flows from credential stuffing and fake account creation as the company scaled
  • AI-resistant interactive challenges stopped automated attacks without adding friction for legitimate customers
  • Device ID added to allow persistent device recognition of low-and-slow automation
  • Expanded again to combine bot management with device intelligence, with both teams building toward stateful Device ID for agent and MFA-bypass detection
”
No serious fintech thinks fraud is ever 'solved'. You manage it. What Arkose Titan changed for us is the economics: attacking us got expensive, so automated attacks and account takeovers are massively down. My team spends far less time on manual review and more on the threats that actually need a human.
— Sean Hederman, CTO, Zilch

BUSINESS RESULTS

  • 37,000 automated attack attempts handled in 4 hours with minimal manual intervention; over 99.4% of credential stuffing attempts stopped immediately.
  • Total cost to mitigate the attack: $7.78 in SMS messages, versus potentially tens of thousands of dollars in downstream ID verification charges.
  • Volumetric credential stuffing attacks eliminated.
  • Nearly 97% of traffic flows through transparent mode, meaning only 3% is challenged — a critical outcome for a fintech company focused on minimizing friction for legitimate users.
  • Security teams freed from overnight escalations to focus on strategic priorities.
”
The future of fraud prevention isn't just about stopping today's bots. It's about building systems that can identify when you're dealing with intelligent agents versus simple automation.
Kevin Gosschalk, CEO, Arkose Labs

Block bad traffic.
Welcome good humans and good agents.

Talk to Our Experts