Hextner
VerifIPDetectBTPricingDocsSupport
Sign inStart free →
  1. Hextner
  2. Glossary
  3. Credential stuffing

What is credential stuffing? 

Credential stuffing is an attack in which stolen username and password pairs are tried automatically against a website’s login form to take over accounts.

It works because people reuse passwords. A list leaked from one site is replayed against many others, usually by scripts or headless browsers, and spread across many IP addresses through proxies so that per-IP rate limits do not trigger. Even a small success rate on a large list means many taken-over accounts.

How do you defend against credential stuffing?

Defences work best in layers:

  • Bot detection on the login route, verified on your server.
  • Network reputation: datacenter, proxy, VPN and Tor addresses, and addresses on attack blocklists.
  • Rate limits per account and per network, not only per IP address.
  • Multi-factor authentication, and refusing passwords known to be breached.

How Hextner uses it

On a login route, verify a DetectBT token on your server and treat the route as sensitive: refuse a bot verdict or a forged token, refuse an expired token, and a missing one unless DetectBT's own health check shows it is down, and accept each token once by recording its jti. From the same handler, call VerifIP's /v1/check for the address's verdict, its proxy, VPN, Tor and datacenter flags, and its attack-feed listings. The DetectBT decision table lists every case.

Related reading

  • Headless browser
  • Residential proxy
  • Datacenter IP
  • IP fraud score

Browse every definition in the glossary.

Hextner

Adversarial traffic detection for teams that ship to the open internet.

Product

  • VerifIP
  • DetectBT
  • Pricing
  • Documentation

Company

  • Support
  • Release notes
  • Talk to sales
  • Get an API key
  • Console

Resources

  • Glossary
  • Use cases
  • India

Stay in the loop

Release notes (also as an RSS feed), new signals, and the occasional write-up on how detection actually gets evaded.

Create an account →

This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP blocklist data: The Spamhaus Project (DROP). Phishing data: PhishTank, CC BY-SA 2.5. Malware data: abuse.ch. Hextner uses the IP2Proxy LITE database for IP geolocation. Full notices: Data sources.

© 2026 Hextner. All rights reserved.
Privacy PolicyTerms of ServiceData sources