RandomUser
New Member
- Joined
- Mar 2, 2026
- Messages
- 7
- Reaction score
- 0
Hey everyone,
This is a massive alert for the entire affiliate community. A highly organized commission theft system has just been uncovered. If you are sending traffic to BetmenAffiliates brands, you are actively being robbed.
MUST READ THE FULL PDF HERE :
htt ps:/ /drive.google.co m/file/d/1auMAKaTh03jDiBqChfMFhtwVEQIHnfQG/view?usp=drive_link
The TL;DR
️How the Scam Works
They used double Base64 encoding and obfuscation to hide the script. Here is exactly how they steal your players:
1. The Wipe: When a user clicks your link, the script scans for affiliate parameters like bta=. If detected, a random lottery decides if the traffic gets stolen. If chosen, it aggressively wipes all your cookies, trackers, and session variables.
2. The Redirect & Swap: The user is instantly redirected through a third-party affiliate platform (partners.trackopia.com/click?aid=978&oid=275). The player drops back onto the casino site, but your unique ID is completely gone. It is replaced with the fraudster's ID (bta=42786 and nci=5903).
The Soft2Bet Connection?
Since we know these brands operate on it, it raises a massive question for the community: Could this be a malicious addon tied directly to the Soft2Bet platform? Given how deeply this script is integrated into the site's HTML to intercept traffic, it is a possibility we need to look into.
Both the BetmenAffiliates and Trackopia platforms hold the true identity and banking information associated with the fraudster's IDs (bta=42786 and aid=978). Check your stats, check your mobile traffic drops, and demand answers!
This is a massive alert for the entire affiliate community. A highly organized commission theft system has just been uncovered. If you are sending traffic to BetmenAffiliates brands, you are actively being robbed.
MUST READ THE FULL PDF HERE :
htt ps:/ /drive.google.co m/file/d/1auMAKaTh03jDiBqChfMFhtwVEQIHnfQG/view?usp=drive_link
The TL;DR
- A malicious JavaScript file, disguised as an "A/B testing tool," is injected directly into the source code of spingranny.com.
- It intercepts legitimate affiliate traffic and secretly redirects it to steal commissions.
- It steals up to 30% of affiliate marketing traffic and up to 35% of organic traffic.
- This is a multi-site operation deployed across at least three casinos: spingranny, spinmama, and vincispin.
️How the Scam Works
They used double Base64 encoding and obfuscation to hide the script. Here is exactly how they steal your players:
1. The Wipe: When a user clicks your link, the script scans for affiliate parameters like bta=. If detected, a random lottery decides if the traffic gets stolen. If chosen, it aggressively wipes all your cookies, trackers, and session variables.
2. The Redirect & Swap: The user is instantly redirected through a third-party affiliate platform (partners.trackopia.com/click?aid=978&oid=275). The player drops back onto the casino site, but your unique ID is completely gone. It is replaced with the fraudster's ID (bta=42786 and nci=5903).
The Soft2Bet Connection?
Since we know these brands operate on it, it raises a massive question for the community: Could this be a malicious addon tied directly to the Soft2Bet platform? Given how deeply this script is integrated into the site's HTML to intercept traffic, it is a possibility we need to look into.
Both the BetmenAffiliates and Trackopia platforms hold the true identity and banking information associated with the fraudster's IDs (bta=42786 and aid=978). Check your stats, check your mobile traffic drops, and demand answers!






