How to Fix Shopify Checkout During a Bot Attack
Card-testing bots flooding your store? Here is how to fix Shopify checkout when fake carts pile up and which defenses actually stop them.

Card-testing bots flood Shopify checkout by hitting your store's myshopify.com subdomain directly, which bypasses any Cloudflare rules you set on your custom domain. To fix Shopify checkout when this is happening, switch to the three-page checkout layout in Settings > Checkout, disable abandoned checkout emails to protect your sender reputation, and as a last resort require customer login before checkout. The login fix works but cuts conversions sharply, so test it on your store before treating it as the answer.
Open Orders > Abandoned checkouts in your Shopify admin right now. If the last fifty entries share a generic name like "John Doe," rotate through fake-looking emails and shipping addresses, and almost all target your single cheapest product, you are looking at a card-testing bot wave, not organic abandonment. The pattern usually starts with a jump from a dozen carts a day to several hundred, and most of the standard defenses (Cloudflare rules, hCaptcha, IP-range blocks, App Store bot-protection apps) do not stop it because the bots hit your myshopify.com subdomain directly.
Why is my Shopify checkout flooded with fake carts?
Your checkout is a card-testing target. Criminals with lists of stolen credit card numbers run small test purchases to validate which cards are still active before using them on bigger transactions, and Shopify's checkout is convenient infrastructure for that test. The same automated systems that hit your store today are hitting thousands of others, so treat it as broad platform abuse rather than anything aimed at you specifically.
The most common signature looks like this: hundreds to thousands of new abandoned checkouts a day, all using a generic name like "John Doe," all rotating through different fake email addresses and shipping addresses, and almost always targeting your single cheapest product. The bots are not interested in the candle or the t-shirt. They are using your cheapest line item as a small-amount validator that minimizes the bank's fraud-flag risk.
A second pattern looks similar but skips payment attempts entirely. Bots generate add-to-cart events and abandoned checkouts by the hundreds without ever reaching a card form. Theories about what these bots are actually doing range from store cloning to AI training data harvesting to competitive product scraping. Merchants in the public threads could not pin down a single motive, and you probably will not either.
The first thing to know is that you are not being charged for any of the declines. Shopify Payments only bills processing fees on completed transactions. The failed card attempts in your order log do not generate fees, and the abandoned checkouts do not cost you in dollars. They cost you in data integrity and email reputation, which is its own problem, but the processing bill is not running.
How do I tell card testing apart from generic spam?
Open Shopify admin and go to Orders > Abandoned checkouts. Sort by date and look at the last twenty entries. If most of them share the same customer name, target the same product, and rotate through obviously different emails and shipping addresses, you are looking at a card-testing or checkout-flooding bot wave, not organic abandonment.
Click into any of those abandoned checkouts and check the payment attempt detail. If the entry shows a declined card flagged as high risk, the bot pushed a payment. If there is no payment attempt at all, the bot stopped at the checkout form. Both are bot patterns, but they call for slightly different responses.
The other tell is sessions versus conversions. A merchant we have seen logs from saw 1,500 to 5,000 bot sessions per day from a single IP block in Ashburn, Virginia, none of which converted, while their organic conversion rate held steady. That ratio is the giveaway. Real visitors convert at some non-zero rate, and a perfectly flat conversion line on a sudden traffic spike is bot-shaped.
Why does Cloudflare not stop these bot attacks?
This is the detail that ruins most merchants' first week of remediation. Every Shopify store has a default subdomain at yourstore.myshopify.com, and that subdomain routes through Shopify's own enterprise Cloudflare account, not yours. When a bot attacks the myshopify.com endpoint directly, none of the Cloudflare rules, rate limits, or geographic blocks you have configured on your custom domain apply. You can spend $200 a month upgrading Cloudflare and the attack pattern will not change.
Bots have known about this for years. They do not need to load your storefront at all. The attacker's script can construct a cart URL using Shopify's documented cart parameters, push the variant ID and quantity, and skip directly to the checkout page on the myshopify.com host. Your homepage, your product pages, your custom-domain WAF: all bypassed.
The myshopify.com gap is a platform-level limitation. You cannot patch it from your admin. Shopify support will not apply custom backend blocks for individual stores. Understanding this point is what saves you from spending a week on the wrong fix.
How do I fix Shopify checkout when bots are attacking right now?
To fix Shopify checkout under active attack, work the list in order. The earlier steps are reversible and low-cost. The later ones trade conversions for protection, so test them carefully.
-
Disable abandoned checkout emails temporarily. Go to Settings > Notifications > Customer notifications and turn off the abandoned checkout sequence. Bot-generated fake addresses cause hard bounces, and a wave of bounces tanks your sender reputation across every domain you mail from. Re-enable the emails after the attack passes and your bounce rate stabilizes.
-
Switch to the three-page checkout layout. Go to Settings > Checkout > Configurations > Customize, then change Checkout Layout from one-page to three-page. This adds round trips that simple bots fail to complete. Several merchants reported volume dropping noticeably within 24 to 36 hours, though sophisticated bots adapt over a week or two.
-
Set Customer accounts to Optional or Disabled, not Required. Go to Settings > Customer accounts and confirm new account creation is not auto-enabled. If your store currently auto-creates an account on every checkout, John Doe accounts will accumulate by the thousand. One merchant had to delete more than 2,000 fake accounts and 1,000 abandoned carts before they noticed the auto-creation toggle was the source.
-
Require customer login before checkout if the attack persists. This is the only setting confirmed to fully stop the attacks. The trade-off is sharp: one agency documented a 95% conversion drop after enabling it, because guest checkout is how most small Shopify stores actually convert. Express checkout options like Shop Pay, PayPal, and Google Pay still work post-login, which softens the blow but does not erase it. Test for a week and watch your conversion rate hour by hour.
-
File a support ticket with quantified data. Shopify's standard reply to bot complaints is generic. A ticket that includes specific numbers, fake checkout volume per day, duration of the wave, abandoned-cart cleanup time, and email reputation impact, has a better chance of escalating to the fraud-prevention team that can do something. One April 2026 thread shows a Shopify product manager engaged publicly when a merchant posted with hard numbers; abandoned checkouts had grown by roughly a fifth in the four weeks following Shopify's claim that protections had been strengthened.
| Defense | Stops attack? | Conversion impact |
|---|---|---|
| Cloudflare on custom domain | No, myshopify.com bypass | None |
| hCaptcha or reCAPTCHA add-ons | Partial, slows volume | Low to medium |
| Three-page checkout layout | Reduces, does not eliminate | Low |
| Customer accounts disabled | Reduces account spam, not checkout flood | None |
| Require login before checkout | Yes, fully | High, around 95% in one case |
If the configuration choices feel tangled, a help1 expert can walk through your checkout settings with you and recommend the right combination for your store size and risk tolerance. We have seen enough of these attacks now that the diagnosis usually takes ten minutes.
What if Shopify's own captcha is blocking real customers?
Shopify automatically deploys a checkout captcha when its systems flag suspicious traffic against your store. The captcha is supposed to filter bots; in practice, several merchants have reported it blocking legitimate customers without any visible toggle in admin to disable it. One Grow plan merchant tracked a noticeable sales drop to the captcha appearance, found no setting to turn it off, and considered switching platforms.
There is no clean fix for this on the merchant side. The captcha is a Shopify-controlled defense, not a setting you own. What you can do is open a support ticket the moment your checkout conversion rate drops alongside captcha appearance, and ask whether your store is currently flagged for extra security checks. Sometimes the flag clears on its own once the bot wave subsides. Sometimes a support agent can escalate it.
The asymmetry is real. Bots reach the checkout via the myshopify.com path that the captcha may or may not protect, while legitimate customers on the custom domain hit the captcha first. The help1 store scanner flags whether your conversion rate is dropping in patterns consistent with the captcha, which gives you data to bring to support instead of a vague complaint.
How do I prevent this from happening again?
There is no permanent prevention right now. The myshopify.com gap is a platform-level limitation, and bot-attack volume is a moving target. Bot fraud roughly doubled year over year in 2024, and industry analysis showed bot traffic to retail sites multiplying more than five times during 2025. Whatever you set up today will be tested again.
What you can do is stand up a routine that catches the next wave early. Once a week, open Orders > Abandoned checkouts and scan for the John Doe pattern. Watch your sender-reputation score in Mail Tester or Postmark. Keep your three-page checkout layout in place even when traffic is calm; the small friction cost is much smaller than the cost of a fresh wave hitting an unprotected one-page checkout. If the captcha ever appears, screenshot it and open a ticket immediately. Do not wait two weeks for sales to drop.
For the related question of why your shipping rates show wrong at checkout once the bot situation has passed, see our guide on how to fix Shopify checkout shipping rates. The same Settings > Checkout area covers both, and a clean shipping config is one fewer variable to debug when something else goes sideways.
Open Shopify admin now, go to Settings > Notifications > Customer notifications, and switch off the abandoned checkout email sequence if your fake-cart count is climbing this week. That single move protects your domain reputation in the next ten minutes regardless of which deeper fix you eventually pick. If the wave is bigger than this guide can cover, a help1 expert can audit your checkout config and walk you through the trade-offs in a free session.
Still stuck? Talk to an expert.
Our vetted Shopify experts can fix this issue for you in a live session. $39 per session. Your first 15 minutes are free.