First-party fraud. The case our whole argument does not reach

This is the page where identity verification stops helping, and we would rather write that than stretch an argument to cover it. First-party fraud is not-built.

What it is

The genuine account holder commits the fraud themselves. They apply with their own identity, pass every check honestly, and then behave dishonestly: disputing transactions they made, defaulting on credit taken with no intention to repay, or abusing a promotion, refund or returns policy.

It is called first-party because the fraudster is the customer, not an impostor.

Why identity verification cannot address it

Every identity control we build answers the question "is this person who they claim to be?"

In first-party fraud, the answer is yes, and that is exactly the problem. The identity is genuine, the verification was correct, and the fraud happens afterwards in behaviour rather than in identity.

That means:

  • Account takeover's step-up argument does not transfer. Asking the person to present a credential proves they are present, and they are present. Proving presence proves the wrong thing.
  • A stronger check does not help. You could verify to the highest assurance available and change nothing about the outcome.
  • Even biometrics do not help, for the same reason. The right person is doing it.

This is the clearest boundary of the whole product category, not just of ours: identity infrastructure answers who, and first-party fraud is a question about intent and behaviour. Detecting it means behavioural analytics, credit and affordability data, velocity patterns, network analysis across accounts, none of which we have or are building.

The one thing worth saying, and it is small

A durable, portable identity makes a fraudster harder to erase and re-create. Someone who burns a reputation under a verified identity cannot as cheaply become a fresh customer elsewhere, which is the accountability side of portability, and it is a long-run ecosystem property, not a control you can deploy this quarter.

We are not claiming it as a mitigation, because it requires an ecosystem of relying parties that does not exist yet, and because a page that turns a genuine limitation into a benefit is doing the thing this estate exists to avoid.

Keep reading

Powered by the Protocol

Solidus Verify is one product on the Solidus Network.

Explore the consensus, the validator economics, and the other products on the same identity layer.

First-party fraud. The case our whole argument does not reach · Solidus — Solidus Verify