Account takeover, where identity binding actually helps

Solidus does not ship an account-takeover product, and there is no ATO detection, device intelligence or behavioural analytics in anything we build.

But unlike most of the pages in this section, there is a real angle here, and it is worth stating plainly before bounding it.

What it is

Someone other than the account holder gaining control of an account: through credential stuffing, phishing, SIM swap, session hijacking, or social engineering of a support desk.

The defining property is that everything looks legitimate. The credentials are correct. The device may be known. Nothing in the transaction is anomalous except that the human at the keyboard is the wrong human, which is why detection leans on inference (device fingerprints, behavioural signals, velocity) rather than on evidence.

The real angle, stated plainly

Authentication proves possession of a credential. It does not prove the presence of a person. That gap is what account takeover exploits, and it is the gap a verifiable credential presentation can close at a specific moment.

An account holder who holds a credential bound to them can be asked to present it at the moments that matter, a large withdrawal, a change of registered device, a new payee, a support-desk escalation. The presentation demonstrates the holder is present, not merely that a secret is known. Holder binding is the mechanism.

The argument is good; what is unverified is our implementation, not the shape of the idea.

The bounds, which are substantial

It is a step-up mechanism, not detection. Something still has to decide when to ask. That decision is risk scoring and device intelligence, not ours. We can answer the question; we cannot tell you when to ask it.

It only works for people who hold a credential. For a book of existing account holders who do not, this is an argument about a future state, the same precondition stated on remediation.

It does nothing for first-party fraud, where the account holder is the person acting and later disputes it. Proving presence proves the wrong thing there.

And a step-up the attacker can also complete defeats itself. If the credential lives on the device the attacker has taken over, presenting it proves nothing. The value depends on the credential being held somewhere the attacker is not, which is a wallet-custody question, not a credential one.

Keep reading

Powered by the Protocol

Solidus Verify is one product on the Solidus Network.

Explore the consensus, the validator economics, and the other products on the same identity layer.

Account takeover, where identity binding actually helps · Solidus — Solidus Verify