Home / Glossary / Credential Stuffing

What is Credential Stuffing?

Credential stuffing is an automated attack that replays username and password pairs leaked from other breaches against your login endpoint, counting on people reusing passwords.

How it works

Bots cycle through millions of stolen pairs at low speed per IP to stay under rate limits. Each success is an account the attacker now controls.

Why it matters for web3

Replayed logins crack user accounts, drain stored value, and trigger fraud disputes that land on your support queue. For your community, that means your allocations stay protected and real holders get a fair experience.

How ValidatorWall detects it

ValidatorWall scores every request against behavioral, network, and device signals, so automated patterns surface even when they imitate real real holders. Suspicious sessions get challenged or blocked before they reach your community.

Related terms