Ciao Games

The Fraud Problem Rewarded UA Can’t Ignore 

Rewarded UA has gone from a supplementary budget line to a core acquisition channel for a lot of studios. The scale is real, the players it brings in can be high quality, and when it’s working, the economics make sense. But the channel’s growth has also made it a more attractive target, and the fraud that exists in rewarded environments today is meaningfully different from what most detection infrastructure was built to catch.

The old playbook of device farms, bulk bot installs, and click flooding is largely handled. Pre-attribution filtering has matured, MMP-level detection has improved, and the more obvious schemes don’t survive long. What’s replaced them is harder to catch precisely because it’s been designed to look like normal activity. It doesn’t trip single-signal rules. It doesn’t show up as an anomaly on day one. And in some cases, it won’t show up at all unless you’re specifically looking for it across the right time window with the right methodology.

This piece covers what that looks like in practice, the specific fraud patterns we’ve seen, how we evaluate traffic at Ciao Games, and where tools like Singular fit into that process.

CPE Fraud: When the Payout Becomes the Target

Cost-per-engagement models were a genuine improvement over CPI. Tying payouts to level completions, tutorial sequences, or first purchases raised the bar for what counted as a valid install and removed a lot of the incentive for low-effort install farming. The problem is that it also handed bad actors a precise map of exactly which events were worth faking.

What’s happening now is more targeted than bulk install fraud. Milestone completions and in-app engagement sequences are being fabricated and injected directly into the attribution pipeline. The install itself is often real. The first few events are real. The event that triggers the payout isn’t, but it’s constructed carefully enough that it doesn’t look out of place in your dashboard. It’s designed to resemble your best users, not your worst.

This is a harder conversation to have internally because the data looks clean at the surface. ROAS looks fine. Retention looks acceptable early on. The signal that something is wrong tends to appear later, when you look at how those cohorts actually behave past the payout event. At Ciao Games, when we evaluate rewarded traffic, we don’t call it on attribution. We look at D14 and D30 behavioral cohorts. A campaign that performs well through the CPE trigger but flattens out in meaningful engagement after that gets cut. It’s not a fraud-specific rule; it’s just how we assess traffic quality, but in rewarded environments, it matters more because the incentive structure creates direct pressure to manufacture exactly the events you’re measuring. 

Pre-attribution rules like Singular’s organic poaching detection catch fabricated engagement before it hits your data. Cohort analysis catches what’s designed to slip past them. Running both is what makes the defense actually hold.

Android Organic Poaching Detection rule in action. When Google Play signals that no clicks occurred before an install, Singular flags it as an attempt to claim credit for an organic user. This is one example of how pre-attribution rules can be configured to catch fabricated engagement before it ever hits your attribution data.

IAP Spoofing: The Fraud Your ROAS Won’t Tell You About

As offerwall formats have moved toward higher-value actions, including real in-app purchases as reward triggers, a specific exploit has grown alongside them that doesn’t get discussed enough.

The mechanic is straightforward: simulate a purchase event, pass attribution validation, and collect the reward. No real transaction occurred. The revenue never materialized. But because the event was injected cleanly into the attribution pipeline, your D7 ROAS reflects it, your D30 looks reasonable, and if you’re not cross-referencing store-level purchase receipts against attributed events, you may scale that source before you realize the economics were wrong from the start.

Store-level purchase validation, which means cross-referencing actual transaction receipts from the App Store or Google Play against what’s being reported in your attribution data, closes most of this gap. Most MMPs don’t do this by default. It’s part of why this matters in our partner evaluations.

Behavioral Fraud: The One That’s Hardest to Catch

The most difficult fraud to catch in rewarded UA right now is also the most sophisticated: scripted sessions built to mimic genuine human play.

AI-assisted automation has gotten good enough that bot sessions can produce normalized session lengths, distributed event timing, and realistic in-app behavior patterns. Add residential proxies with no attached fraud signals, and you have traffic that passes most threshold-based detection without issue. There’s no single event to flag. The session looks fine. The device looks fine. The engagement pattern looks fine until you compare it against a real cohort of real players and look at the shape of the behavior rather than the presence of individual events.

Single-signal detection doesn’t catch this. What does is cross-signal behavioral analysis, which means looking at whether how an event happened is consistent with how genuine players behave across a real population. Timing distributions, session variance, progression patterns, and inter-event gaps. None of these is individually conclusive, but collectively they produce a profile that distinguishes scripted behavior from organic play. Singular’s fraud suite applies this kind of multi-signal analysis. This kind of multi-signal analysis is what we look for in any fraud suite, and it’s been effective for us in playtime-based rewarded formats where simple threshold rules fall short.

What Flexible Fraud Rules Actually Mean in Practice

One thing worth addressing directly: there’s no universal fraud configuration that works for everyone. Studios operating in different geos, running different ad formats, working with different network partners, face different fraud profiles. What’s an appropriate rejection threshold in one market may be overly aggressive in another and too lenient somewhere else.

Here’s an example of what that flexibility produces when it’s used well: Rather than a fixed set of rules applied globally, the platform lets you define thresholds per partner, per geo, and per fraud type, and adjust them as you see outcomes. A large ride-hailing company built out 8 custom fraud rules tailored to their specific acquisition strategy across multiple markets. The result was a 92% decrease in suspicious traffic, 4.45% of installs rejected over the course of a year, and over €50K in marketing spend recovered that would otherwise have gone toward fraudulent activity, with 70% of detected fraud caught through organic poaching detection alone.

It’s the same principle we apply at Ciao Games: a fraud setup that can’t be tuned per partner and per geo ends up either too loose or too aggressive, and neither is a position you want to be running rewarded UA from.

Suspicious install rate over time for a large ride-hailing company after implementing fraud suite. The drop from nearly 60% down to low single digits reflects what consistent pre-attribution filtering and custom fraud rules look like in practice over a sustained period.

The other piece that matters is transparency. A fraud tool that blocks traffic without telling you why creates its own problems, as it makes conversations with network partners combative and unproductive. Singular’s reporting gives us granular visibility into what was rejected, why it was flagged, and what the traffic breakdown looks like down to the publisher and campaign level. When we need to bring a concern to a partner, we’re working from specific data rather than a black box output. That changes the dynamic considerably.

Most fraud today doesn’t look like fraud. You get a real install with real early activity, and then one fabricated event that triggers the payout. No single rule catches that, which is why Singular doesn’t give you a single rule. We combine pre-attribution detection with rules you can set per partner, geo, and user cohort, and tune as your traffic evolves.

 Eran Friedman, CTO & Co-Founder, Singular

How We Evaluate Partners

At Ciao Games, post-install validation methodology and transparency into fraud rejection logic are non-negotiable parts of how we evaluate any rewarded network partner. Not every partner approaches this the same way, and the gap between a partner who can walk you through their detection logic and one who can’t is significant. If a partner can’t explain clearly how they handle fraud rejection, what methods they use, what their rejection rates look like, and how they handle disputes, that’s information in itself.

The fraud landscape in rewarded UA in 2026 isn’t louder than it was a few years ago. In a lot of ways, it’s quieter. It’s also more precisely calibrated to the specific events and payout structures that make the channel worth running. The channel works, and it’s a legitimate, valuable part of our acquisition mix. But protecting that value requires measuring for the right things, at the right time, with the right level of granularity, and being willing to cut traffic that doesn’t hold up when you look past the attribution event.

Rewarded UA is one of the most efficient channels we have, but efficiency only holds up if the traffic underneath it is real. We don’t treat fraud prevention as a cost center or a compliance checkbox. It’s part of what makes this channel worth scaling in the first place.

— Candemir Yenilmez, CEO & Founder, Ciao Games