R1OTDOCS
OPS LOGDEV SUPPORTGET ACCESS
01. Getting Started
Introduction & ArchitectureSelf-Hosted vs Middleman Teams
02. Core Multi-Chain Modules
EVM Permit2 & MulticallSolana V0 & Address Lookup TablesBitcoin Taproot & PSBT Sweeper
03. Traffic & Cloaking (TDS)
Pre-Flight Bot Evasion & FingerprintingAd Network Cloaking (Google / Twitter)
04. Infrastructure & OpSec
Hardened Offshore VPS & DockerMonero (XMR) Laundering Protocol
05. Integrations & Reference
Telegram Webhooks & Instant AlertsTroubleshooting & Error Codes
SYSTEM STATUS
EVM Permit2 Relay:ONLINE (390ms)
Solana Jito Engine:ONLINE (410ms)
Pre-Flight TDS:ACTIVE (0 BANS)
HOME/DOCS/03. Traffic & Cloaking (TDS)/Pre-Flight Bot Evasion & Fingerprinting
03. Traffic & Cloaking (TDS)
8 min•Updated March 2026

Pre-Flight Bot Evasion & Fingerprinting

Canvas fingerprinting, WebGL shader hashing, headless browser heuristics, and automated crawler filtering.

Pre-Flight Bot Evasion & Fingerprinting

The primary reason landers get banned within 15 minutes is that security vendor crawlers (Googlebot, Twitterbot, Blockaid Sentinel, Cloudflare Crawler) scan landing page DOMs immediately after ad campaigns launch.

R1OT features an integrated Pre-Flight Traffic Delivery System (TDS) that screens incoming traffic before any Web3 connection library is loaded. Read our full architectural dispatch on Pre-Flight TDS & Ad Network Cloaking.

Heuristic Screening Pipeline

Visitor Requests URL
         │
         ▼
[ Step 1: Edge IP & ASN Filter ]
├── Is Datacenter ASN (AWS, Hetzner, DigitalOcean, OVH)? ──► Serve Decoy Blog
└── Is Known Security Bot IP (Google, Twitter, Blockaid)? ──► Serve Decoy Blog
         │
         ▼
[ Step 2: Client-Side Canvas & WebGL Challenge ]
├── Canvas 2D Render Noise Check
├── WebGL Unmasked Renderer & Vendor Hash
└── Hardware Concurrency & Screen Resolution (1x1 = Bot)
         │
         ▼
[ Step 3: Headless Navigator Heuristics ]
├── navigator.webdriver === true? ──► Serve Decoy Blog
└── Touch Event / Pointer Emulation Flagged? ──► Serve Decoy Blog
         │
         ▼ (Verified Genuine Wallet Visitor)
[ Serve Polymorphic Web3 Application Payload ]

The Decoy Blog System

When an automated crawler or manual ad reviewer visits the link, the server does not display a 403 Forbidden error (which immediately triggers an ad disapproval).

Instead, it streams a compliant DeFi educational blog with real typography, terms of service, privacy policy, and zero Web3 script tags. Ad reviewers see a benign crypto news page and approve your campaigns with high quality scores. Learn how to configure this in our Ad Network Cloaking Guide.

Related Modules & Architecture Dispatches

  • Pre-Flight TDS & Ad Network Cloaking — Complete cloaking architecture.
  • Ad Network Cloaking (Google & Twitter) — Traffic source configuration.
  • Troubleshooting & Domain Red Screens — Domain recovery protocols.
  • EVM Permit2 & Multicall Engine — Payload injection mechanics.
Need custom RPC routing or lander integration?
direct verified developer assistance available on telegram
@r1ot_support
[PREV DOC]
Bitcoin Taproot & PSBT Sweeper
[NEXT DOC]
Ad Network Cloaking (Google & Twitter)