Multi-Accounting Detection: Stopping Gnoming and Chip-Dumping

PhishFort Team
PhishFort Team
6 min read
Multi-Accounting Detection: Stopping Gnoming and Chip-Dumping

Multi-accounting detection is the practice of identifying when a single person controls more than one account on a platform, usually to bypass a limit, rule, or restriction the platform put in place on purpose. In iGaming, this shows up most often around deposit limits, self-exclusion, and bonus caps, whereas in poker and other skill-based games, it takes on a more targeted form: gnoming and chip-dumping.

This piece is part of PhishFort’s broader work protecting gambling and betting platforms. For the full picture on fraud detection across iGaming generally, see our iGaming fraud prevention guide, the account-correlation techniques described there apply directly to gnoming and chip-dumping too. Here, we’re going deep on this one specific pattern.

Why Multi-Accounting Isn’t Just a Bonus Problem

It’s easy to file multi-accounting under bonus abuse and move on, but that undersells what’s actually at stake. A player opening a second account to dodge a deposit limit or a self-exclusion restriction isn’t just gaming a promotion, they’re circumventing a responsible-gambling control the operator is often legally required to enforce. Regulators treat that differently than ordinary fraud, and operators that can’t catch it face compliance exposure on top of the financial loss.

Gnoming: When Multi-Accounting Becomes Collusion

In poker specifically, multi-accounting takes a more deliberate form known as gnoming. One player controls two or more seats at the same table, allowing them to team up against unsuspecting, honest players. Gnoming is hard to catch through gameplay analysis alone, because the accounts are designed to behave like separate people. The tell is almost always in the infrastructure underneath the accounts, not in how they play.

Chip Dumping in Poker: Multi-Accounting as a Laundering Mechanism

Chip dumping in poker is a form of multi-account fraud where one controlled account deliberately loses chips or funds to another at the same table. It functions as a value-transfer mechanism: moving money between two accounts the same individual or group controls, without triggering the transaction-monitoring checks that would flag a direct wallet-to-wallet transfer. Unlike gnoming, which exploits an information advantage, chip dumping is a financial exploit. The goal is to move value, not to win hands.

Why poker is the primary format for this scheme

Cash games and tournament formats both expose platforms to chip dumping, but the mechanics differ in ways that matter for detection.

In cash games, chip dumping is typically gradual. One account runs consistently bad against a specific opponent across many sessions. Each individual hand is explainable as a bad beat or a wrong read. Across fifty hands, the unidirectional flow of value toward one specific account becomes the signature. The money laundering mechanic is straightforward: buy in with funds linked to fraud elsewhere on the platform, systematically lose chips to a clean-looking account, then cash out from the clean account. No single transaction is suspicious. The pattern is.

In sit-and-go tournaments, chip dumping tends to be faster and more visible. A controlled account goes all-in early holding a weak hand against a target account with a strong one. The chip transfer happens in a single hand. The dumping account busts out, which generates no further scrutiny. The target account finishes in the money and withdraws. Operators focused on late-stage tournament irregularities often miss early-hand all-in patterns that do not fit the stack sizes involved.

What detection actually requires

Three independent signal types need to converge before a chip dumping case is actionable:

Fund flow graphs. The core signature is persistent unidirectional chip movement between specific account pairs. Normal players distribute losses across many opponents over time. A chip-dumping pair shows one account losing value to one specific account, repeatedly, across sessions that may span days or weeks. Fund flow alone is a flag, not a finding.

Account clustering signals. Device fingerprinting, shared IP ranges, and behavioral timing patterns, including login windows, session start times, and fold patterns, confirm whether two accounts are likely operated by the same person or group. The combination of fund flow evidence and account clustering is what separates a chip dumping case from a player who is simply losing to a better opponent.

Registration and payment metadata. Shared payment methods, phone numbers tied to the same carrier, or linked KYC document data serve as secondary confirmation when the primary signals are already present. They are rarely sufficient on their own but frequently decisive when combined with the above.

No single signal is conclusive. Chip dumping enforcement in a regulated environment requires the combination to cross a threshold consistent with the platform’s evidentiary requirements and its licensing jurisdiction. For platforms operating under multiple licensing regimes, that threshold may vary by market.

How Multi-Accounting Detection Actually Works

Catching this reliably comes down to correlating signals that don’t show up in any single account’s history on its own.

Device fingerprinting. Accounts that share a device, or a small cluster of devices, are the first and strongest signal. This is the same underlying technique used across iGaming fraud detection generally, it’s not a separate system, just applied with multi-accounting-specific correlation rules.

IP and network correlation. Shared IP ranges, especially residential proxy pools rotating through a consistent set of addresses, are a strong secondary signal when combined with device data.

Behavioral timing patterns. Accounts that consistently play, deposit, or fold in coordinated timing windows, especially at the same table or in the same session, strongly indicate gnoming.

Fund flow analysis. For chip-dumping, the tell is in the transaction graph: consistent one-directional value transfer between a specific set of accounts, especially when it doesn’t match normal win/loss variance.

None of these signals alone is conclusive. Real detection comes from correlating two or three of them together, which is why device fingerprinting and behavioral analytics need to work as one system rather than separate tools bolted together.

What This Means for Operators

If your platform includes poker, skill-based games, or any format where players compete directly against each other rather than against the house, multi-accounting detection deserves its own attention within your broader fraud prevention setup, not just a general bonus-abuse rule. The underlying detection infrastructure, device fingerprinting and behavioral correlation, overlaps with what’s covered in our iGaming fraud prevention guide, but the specific correlation rules for gnoming and chip-dumping need to be built and tuned on top of that foundation, not assumed to come for free.

Frequently Asked Questions

What is chip dumping in poker?

Chip dumping in poker is a coordinated fraud scheme where one player deliberately loses chips to another controlled account at the same table. Both accounts are operated by the same individual or group. In online environments, it functions as a money laundering mechanism: value moves between accounts without triggering payment-fraud monitoring, because the transfer happens through gameplay rather than a direct transaction.

How do online poker platforms detect chip dumping between accounts?

Detection requires correlating at least three independent signals: persistent unidirectional chip flow between specific account pairs across sessions, device fingerprinting and IP correlation evidence linking the accounts to the same operator, and behavioral timing patterns showing synchronized activity. Individual signals are insufficient for enforcement. The combination, meeting the platform’s evidentiary threshold, is what makes a case actionable.

What is the difference between chip dumping and gnoming in online poker?

Gnoming gives one player an information advantage by controlling multiple seats at the same table simultaneously. Chip dumping uses multiple accounts to move value between them. Gnoming distorts game outcomes for other players at the table. Chip dumping distorts the platform’s financial integrity and, in many cases, launders proceeds from fraud schemes running elsewhere on the platform.

Why is chip dumping harder to detect in tournaments than in cash games?

In cash games, the fund flow pattern builds across many sessions and becomes statistically distinctive over time. In tournaments, a single all-in hand can complete the chip transfer before pattern analysis flags anything. Early-hand all-in plays between accounts with mismatched stack sizes relative to hand strength are the primary signal worth monitoring in tournament formats.

See how PhishFort protects gambling and betting platforms →