Seatext library / BotRefund evidence
Why Coupon Sites Steal Your Affiliate Conversions — And How to Prove It
Coupon sites and browser extensions inject their own affiliate IDs at checkout, overwriting your referral cookie so the network credits them instead of you. The conversion still happens, but the attribution shifts to the...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
After a coupon site promotion, your affiliate network may report fewer conversions for your affiliate ID. The sales still happen. The credit does not go to you.
Coupon sites and browser extensions like Honey or Capital One Shopping wait until a shopper reaches checkout. Then they inject their own affiliate redirect. That redirect overwrites your referral cookie. The network records the sale under the extension's ID. You still pay the discount. You also lose the commission.
This page explains why that happens and how to prove it.
Why the attribution shifts to a coupon extension
Affiliate networks rely on cookies. A cookie stores the affiliate ID that referred the shopper. When a shopper clicks your link, the cookie is set. If another affiliate click happens before purchase, the newer cookie replaces your cookie.
Coupon extensions exploit this. They do not need the shopper to click a coupon first. The extension detects a checkout page and fires its own affiliate link in the background. This is called a cookie overwrite. Last-click attribution means the newest affiliate ID wins. The extension becomes the last click. The network credits the extension, not you.
This matters because you lose more than one conversion. A large coupon site promotion can trigger overlays across many sessions. Your dashboard shows a sudden drop in attributed sales. The real cost is double. You gave a discount. You also pay a commission to a partner who did not bring the customer.
How the hijack works at checkout
Let's step through the sequence.
- A shopper adds products to the cart and moves to checkout.
- The browser extension detects the checkout path or coupon code form.
- It shows an overlay that offers to apply coupons.
- In the background, the extension calls its affiliate redirect URL.
- That call sets a new tracking cookie with the extension's affiliate ID.
- The new cookie replaces your existing referral cookie.
- At purchase, the network credits the extension.
The merchant sees a normal order. The network sees the extension as the referrer. Your affiliate reports show no sale for that session. The overlay may not even be clicked. The redirect fires anyway.
This is why coupon extensions are called a margin drain. They insert themselves into a purchase that was already going to happen.
Coupon sites versus browser extensions
A coupon site can be a legitimate affiliate. It sends a shopper to your store with a click. That click can earn a commission if the shopper buys. The problem starts when a coupon extension injects a new affiliate click after the shopper is already on your site.
Some coupon sites also own browser extensions. The extension may fire the same affiliate ID as the coupon site. In that case, the extension still overwrites a referral that came from your own campaign. The result is the same. Your conversion is reassigned.
This distinction matters. You do not want to stop working with every coupon site. You want to stop automatic overlays that take credit for a sale they did not cause.
Why your affiliate network reports fewer conversions
Your network is not hiding a sale. The sale is still in the system, but it is assigned to another affiliate ID. Your dashboard usually filters by your ID. When the extension's cookie wins, the conversion does not appear in your reports.
Most affiliate networks use last-click attribution. The last affiliate click before the purchase gets the credit. The extension's background redirect happens after your click. That makes it the last click. The network follows its own tracking rule. From the network's point of view, the extension earned the commission.
This can look like a traffic quality problem. You might think the coupon site sent low-quality clicks. That is often not the case. The traffic may be real and ready to buy. The problem is the referral credit being overwritten at checkout.
Diagnostic sequence to confirm coupon-site attribution theft
Use this sequence to confirm the cause. Do not guess.
- Compare click timestamps. Pull the click log for the offer. Look for a referral click that occurs after the cart-add or checkout-load event. A post-cart referral from a coupon extension is a strong signal.
- Check cookie values at checkout. Open browser dev tools and inspect the affiliate tracking cookie on the checkout page. Note the value. Trigger the checkout flow. If the cookie value changes, a script rewrote it.
- Match conversion IDs to extension IDs. Export conversions from the network. Compare the affiliate IDs with known coupon extension partner IDs. Honey, Capital One Shopping, and similar services have partner IDs. A match means the extension got credit.
- Audit referral timelines. Verify whether the referral click happened after the shopper had already added products. If yes, the referral was injected by an overlay. If the click happened before the shopper entered the store, it may be a valid coupon-site referral.
- Run a clean-browser test. Visit your checkout in an incognito window with no extensions. Place a test order. Confirm your affiliate cookie persists through to the thank-you page. If the cookie disappears in this clean environment, the problem is not your tracking.
- Confirm with multiple sessions. One event is not proof. Repeat the test across different browsers and devices. See if the pattern happens only when a coupon extension is present.
If steps 1-4 show a post-cart referral from a known coupon partner, you have confirmed attribution theft.
Technical prevention strategies at the checkout page
You can make it harder for coupon extensions to overwrite your cookies. Start with the checkout page.
- Set strict Content Security Policies (CSP). CSP allows you to block unauthorized scripts from loading. Configure CSP directives so that billing URLs do not load unknown third-party frames. This stops the extension's background redirect from executing.
- Obfuscate coupon field identifiers. Extensions look for stable class names or IDs to detect the coupon code field. If you randomize those names on each page load, the extension cannot find the field. It may not trigger its overlay.
- Track referral timelines. Set up monitoring in your click log. Flag any affiliate click that occurs after a cart-add event for the same session. This gives you an instant alert when an overlay injection happens.
- Deploy client-side telemetry. JavaScript on the checkout page can record the exact timing of every referral cookie write. When a coupon extension cookie appears after the customer has already completed shopping steps, the transaction can be flagged as an override. This evidence is useful for disputes.
These steps do not block a user from manually copying a coupon code. They block automatic background injections. You want to stop the hijack, not the discount.
How BotRefund detects and flags coupon-extension overrides
BotRefund runs client-side telemetry on checkout pages. It records the millisecond timing of referral cookie writes. If the platform sees a coupon extension cookie set after the customer already reached checkout, it marks the transaction as an override.
This flag gives you precise evidence. You can show the network that the extension's referral happened after the shopper was already in your funnel. You can decline payouts to coupon extensions that did not originate the sale.
The same telemetry also captures bot behavior. BotRefund looks for patterns such as superhuman input speed, grid-aligned mouse movement, and absence of human tremor. These signals help separate coupon-extension theft from invalid bot traffic. A bot click and a coupon overwrite are different problems. Both hurt your reports. BotRefund can identify both.
What to do after you confirm the theft
Once you have evidence, act quickly. Save the click logs for the affected sessions. Export the conversion records from the network. Note the extension's affiliate ID and the timestamp.
Contact your affiliate manager. Explain that the referral was injected after the shopper was already in the checkout flow. Provide the sequence of events. Ask them to review the attribution.
If your network allows disputes, file one for each affected conversion. Attach the cookie-timing evidence and the clean-browser test. Be clear that the extension did not originate the sale.
In parallel, apply the prevention steps above. The faster you block the injection, the fewer conversions you lose.
Limitations and when this diagnosis does not apply
Not every coupon-site promotion causes attribution theft. Check these cases before you act.
- If your affiliate network uses first-click or multi-touch attribution, the extension's cookie may not overwrite your credit. First-click locks the credit to the first referrer. Multi-touch splits value. Check your program settings.
- Some networks let you lock attribution to the first referral in a session. Enable that option if it is available. This prevents a late overlay from stealing credit.
- If a shopper manually clicks a coupon site before arriving at your store, that click creates a legitimate referral. The diagnostic sequence separates manual clicks from overlay injections. Pre-cart clicks are valid. Post-cart clicks are suspicious.
- Extensions that only display codes without firing affiliate redirects do not cause this problem. Do not block all coupon tools. Block automatic background injections only.
- One missing conversion may have many causes. Check for ad blockers, cookie deletion, and cross-device journeys. Confirm the pattern before contacting your affiliate manager.
Key facts
| Factor | Detail |
|---|---|
| Primary mechanism | Browser extension injects affiliate redirect at checkout, overwriting existing referral cookie |
| Typical examples | Honey, Capital One Shopping, similar coupon overlays |
| Attribution model exploited | Last-click (default for most affiliate networks) |
| Business impact | Double dip: discount given plus commission paid to extension |
| Detection signal | Referral click timestamp after cart-add or checkout-load |
| Prevention | Strict CSP, obfuscated coupon fields, post-cart referral monitoring, client-side cookie timing telemetry |
Terminology
- Last-click attribution: The conversion is credited to the most recent referral click before purchase.
- Cookie overwrite: A new tracking cookie replaces an existing one, shifting credit to the newer referrer.
- Overlay injection: A script that loads an affiliate redirect URL in the background while showing a coupon UI to the user.
- Client-side telemetry: JavaScript that records browser events such as cookie writes, timing, and mouse behavior during a session.
FAQ
Why does the conversion appear in the network but not in my dashboard?
The network attributes the sale to the extension's affiliate ID. Your dashboard filters for your ID. You do not see the conversion.
Can I block coupon extensions entirely?
You can make injection harder with CSP and obfuscation. You cannot prevent a user from manually copying a code. Focus on detecting and disputing post-cart overwrites.
Does this affect all affiliate programs equally?
Programs using last-click attribution are vulnerable. Programs with first-click lock or multi-touch models are less affected. Check with your affiliate network to confirm your attribution model.
How do I get the commission back?
Use the timestamp and cookie-timing evidence to file a dispute with the network. Show that the referral occurred after the shopper was already in your funnel. Some networks may not reverse the credit, so make the case with data.
Will CSP break legitimate scripts?
Test in staging. Allowlist your own analytics, payment, and chat scripts. Block only unknown third-party frames on checkout URLs. If a script breaks, adjust the allowlist.
What if the shopper clicked a coupon site earlier in the journey?
That is a valid referral. The diagnostic sequence checks whether the click happened before cart-add (valid) or after (overlay theft).
Does BotRefund stop the overlay from loading?
BotRefund detects and flags the override. It provides the evidence to decline payout. Pair it with CSP and field obfuscation to prevent the injection in the first place.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.