Stripe Link exposes merchants to undefendable fraud risk
My business was recently hit by a fraudulent customer who spent over $1200 across multiple transactions over a few days. Every payment was made through Stripe Link.
The problem I discovered afterward is that Link abstracts away the real payment method, without necessarily causing a liability shift against fraud.
Despite enabling multiple layers of protection (Chargeback Protection, extra 3DS credit card authentication, etc), with a specific intent of shifting liability away from my merchant account, these Link payments bypassed all of those settings.
As a former engineer at a payments company, I had assumed that Stripe would do their own authentication before storing a Link payment method, but I was wrong to assume this. Stripe approved all of the fraudulent payments, most without a liability shift, and my business was left holding the loss.
In conclusion: If you run an online business accepting payments via Stripe, I highly recommend turning off Stripe Link until they can correct this issue or allow merchants additional controls over which types of Link payments they accept.
No comments yet.