Transcription
Last year, 18 million people witnessed Honeyish scheme. How they were poaching affiliate commissions from influencers, bloggers, and virtually every player in the affiliate marketing industry. But that wasn't the full story.
Over the past year, I've been digging deep into Honey's code and discovered something huge. In 2017, under the leadership of co-founders Ryan Hudson and George Ruan, Honey secretly engineered a sophisticated system designed specifically to enable this theft while hiding it from industry insiders and compliance testers. Honey achieved this by using incredibly invasive tactics to determine who was using their extension and would adjust its behavior accordingly, making it very difficult for the industry to detect.
It's very reminiscent of the dieselgate scandal where Volkswagen quietly programmed their vehicles to only lower emissions during regulatory testing. Volkswagen executives went to jail for that. But this, in my opinion, this involves intentional, provable theft from thousands of ordinary people by a Fortune 500 company. PayPal has had 5 years to find the system, investigate it, and report it to authorities. Instead, they have made multiple alterations to it and have ultimately allowed it to continue operating.
So, in this video, I'm going to demonstrate what the system is and how it works. I'll also be addressing Ryan Hudson's claims that I misled viewers in my first video, and I'll be doing so with a host of new data, bringing more damning insights into his former company. As always, the views, allegations, and conclusions expressed in the series are my opinions based on evidence I have gathered, which will be shared throughout. Ladies and gentlemen, welcome to the Cookie Gate scandal.
[music]
After publishing part one of my investigation, Honey co-founder Ryan Hudson reached out to me on Twitter, stating he was quote, "Happy to discuss Pi and Honey." For those who don't know, Pi is an ad blocker and coupon cashback extension. You know, one of Ryan's latest startup projects. Very original. Naturally, I immediately jumped at the opportunity to speak with Ryan and asked for an on there interview. Ryan ghosted me for a week. I followed up. He eventually replied and we had a short but very limited chat on X. This ultimately ended with Ryan requesting my full legal name and address to send certified mail so that he could lay out the damaging claims that I allegedly made about his former company. In other words, it appears Ryan was threatening me with a lawsuit. But instead of following through, Ryan posted a lengthy rant about my video in an AMA on Reddit.
Now, Ryan's post attempts to address the two key allegations made in my first video. one, that Honey misled consumers by claiming to always find the best deal, and two, that Honey was poaching affiliate commissions from content creators. According to Ryan, neither of these claims are true. He states that Honey only removed coupon codes that were never intended for public use, like employee discounts. And he insists that if a brand wanted a publicly available coupon removed, Honey required the brand to replace it with a Honey branded code of equal value. He claims this was a strict policy at Honey during his tenure.
Now, unfortunately for Ryan, those claims are not supported by Honey's own data. For starters, Honey literally built a Shopify app that gave store owners access to Honey's database, enabling them to freely add or delete coupon codes as they please. And while this app no longer exists today, an FAQ page for it remains live on Honey's website. In fact, the very first topic on that page titled [music] coupon code management states the following. Choose which coupon codes you'd like to share with Honey. We will automatically pull in all available codes and you choose which ones you'd like to make available to Honey members and which ones you'd like to remove from the Honey system. The only limitations mentioned in this document are that stores had to keep at least one coupon code live at all times. And there is absolutely no stated requirement that this coupon code must be of equal value to the highest publicly available coupon as Ryan claims. And for the record, this app launched in 2021 while Ryan was still working at Honey. So, as you can see, Ryan's story quickly falls apart on its own.
But once you start digging into the data from Honey's database, the situation looks a whole lot uglier. So, let's take a closer look. In the spreadsheet, we can see every store Honey supports along with the unique ID Honey assigned to each brand. We can also see the store's country, when Honey added it to their database, how many Honey users visited in the last 30 days, how many coupons Honey had on file for that store, and whether the store offered cash back, and if so, how much. We also have a dedicated spreadsheet with every coupon code Honey had on file. Now, how many coupon codes did Honey claim to have again? >> Automatically comparing [music] millions of millions of millions of >> millions of coupon millions of promo codes. >> Ah, right. Millions. But how many coupon codes do they really have? Well, at the time this data was collected, Honey only had 85,000 coupon codes, 12,000 of which were expired. That's quite the rounding error.
We can also see that when a coupon code has expired, Honey marks it as hidden. Now, you would think that when a coupon code is expired and marked hidden, that Honey stops offering that coupon at checkout, right? Yeah. No. No, that's not what happens. Instead of removing the coupon code from their system, Honey simply changes the way coupon codes are displayed to users. For example, this store has eight coupon codes, all of which have been expired for several years and are marked as hidden. Yet, if we visit the store page, Honey pops up claiming to have eight available coupon codes. And instead of showing what coupon codes are being applied, Honey is now censoring them. Yikes, that doesn't look good. Even worse, on iOS and Firefox, Honey refers to expired codes as Honey exclusive codes. And as you can see on American Eagle's website, Honey claims to have five available coupon codes. Two coupon codes are displayed, and the other three are labeled Honey exclusive coupon codes tried at checkout. But if we look at Honey's data for American Eagle, we can see that none of the three codes are exclusive, but they are expired and set to hidden. Unfortunately, these are not edge case scenarios. Looking at Honey source code, this behavior certainly looks intentional. And honestly, it makes sense. Showing up with a few codes that don't work still looks better than showing up with nothing at all. In other words, Honey has been wasting your time with expired coupons purely for the optics.
And here's a statistic that blew my mind. At the time this data was collected, Honey had 13,800 stores with absolutely nothing to offer. No cash back, no active coupons, and every single one of those stores was partnered with Honey, meaning Honey was earning affiliate revenue for simply wasting your time. Easy money, baby. That's modern-day affiliate marketing for you.
Now, have you ever wondered where Honey actually gets its coupon codes from? Well, thanks to this data, we can get a pretty clear picture. And this is interesting. 27,000 coupons were intentionally shared by brands themselves through affiliate networks. 23,000 coupons appear to have been manually added by Honey's employees. 9,000 of which are Honey branded codes like Honey 5 or Honey 10. And the rest, well, the remaining 34,000 representing the largest portion of Honey's coupons were [music] sourced from users. In other words, we the consumers were what made the product work so well. [snorts] Go figure. So much for scanning the entire internet for every working coupon code. The only evidence Honey did any kind of scouring comes from this DM Ryan sent me claiming they had a full-time team digging through homepages and email lists. And they probably did, but let's be real, having a team of people scrolling through newsletters is hardly the automated coupon harvesting machine Honey marketed itself as. In fact, I found zero evidence of automation whatsoever. Well, actually, that's not entirely true. If we look at the support notes left by Honey's developers, we can see that back in 2016, Honey was scraping coupons from at least one source, their competitors, Retail Me Not and Coupon Follow. Of course, they were.
So, now that we've established where Honey sourced its coupons from, let's take a further look at how Honey controlled which coupons were made available to users. If we come back to Yelta's spreadsheet and review the monetization notes left by Honey's employees, we can see that there are numerous notes proving Honey did in fact remove coupon codes at a brand's request. For example, this monetization note says disabled Retail Me Not and non-link share coupon sources. L'Oreal family of brands do not allow user generated codes. In other words, for this brand, Honey stopped scraping codes from Retail Me Not, removed all user submitted codes, and kept only the codes which were directly approved by the brand on Link Share. Now, in some cases, Honey went even further, disabling all coupon sources, only allowing one specific coupon to remain live, like this one. Only code PJ Baby allowed, removing all other codes, and disabling all other coupon sources. See, now that doesn't quite align with Honey's marketing claims. Honey will find every working code on the internet and apply the best one to your cart. Hilariously, Ryan told me in our DMs that letting retailers give us shitty codes would, as you've seen in the public outcry, destroy the brand value proposition. George and I aren't that dumb. Well, that's certainly not supported by this evidence. [music]
In fact, the spreadsheet also reveals that Honey had a dedicated feature flag where they could disable user submitted coupons for any store. When this is set to false, users are blocked from submitting coupons for that brand. We can see this in action here. Honey allows me to submit coupon codes for Under Armour, where UGC allowed is set to true, but not for Nike, where it is set to false. And guess what? Honey has this set to false for over 2,000 brands, virtually all of which are, you guessed it, partnered with Honey.
Now, you might think that this service is proof that brands were secretly colluding with Honey to give users shitty deals, but this actually has less to do with the brands and more to do with the fundamental rules of affiliate marketing. And this is where Ryan's argument completely falls apart. You see, most affiliate networks have a very clear set of rules to protect brands from having their coupons leaked online for all the reasons I highlighted in my previous video. These rules explicitly state that brands alone decide which of their coupon codes can be distributed and which ones cannot. This is not just an expectation. It's directly spelled out in most affiliate network terms of service and it's reinforced by industrywide guidelines like the Internet Advertising Bureau's voucher code of conduct. Additionally, brands themselves typically have their own set of rules that you must read and agree to before joining their affiliate program.
This here is my account on the Awin network. Honey 2 will have an account just like this. So, let's pretend I'm Honey and I want to find a new merchant to partner with. Let's check out Nike. Now, if I want to join Nike's affiliate program, notice how Awin requires me to read and agree to Nike's terms of service first. And if we check the terms, you can see that Nike has a dedicated clause for coupon codes, which states, "You undertake not to use any Nike promotional codes or coupons that are not made available through Awin." In other words, if I'm Honey and want to partner with Nike, the only coupons I can share are the coupons that were approved by Nike and provided directly through this network. I cannot publish user submitted coupons. I cannot scrape codes from websites like retail me not and share them with my users because any of those actions would be a contractual violation.
Let's now look at another affiliate network. This time Impact. Here we have the Gapactory affiliate program. Their program terms state you may only advertise coupon codes that are provided to you through the affiliate program. Let's look at another major affiliate network. This time Commission Junction. Here we have NordVPN's affiliate program, and it too states, "Publishers may only use coupons and promotional codes that are provided exclusively through the affiliate program." See what I mean? No matter which affiliate network you're on, you'll find that most merchants have a coupon policy in place for, again, all the reasons I outlined in my last video. The rules are clear. If a brand demands a coupon be taken down, Honey has no choice. They must comply. There's really no argument here. Honey lied to consumers. Plain [music] and simple.
In fact, we can even prove that Honey was well aware of these rules. If we go back to the monetization notes, you can see several examples where Honey noted certain brands as having a coupon clause. And this is where it gets even worse for Honey because they also documented ignoring these clauses. Take a look at these notes. Terms have the coupon clause. No data on enforcement yet. The terms have the coupon clause. We just added them. So unsure if this is enforced yet. Or how about this note on the lid chocolate store has non-affiliate coupon clause but don't have any codes from network so can't remove other coupon sources. Based on these notes, it appears that Honey would join a brand's affiliate program, noted their coupon policies, but would intentionally disregard them for as long as they could get away with it. So Ryan has put himself in a real awkward situation here because his Reddit post effectively serves as an admission that Honey knowingly violated network policies under his leadership. And Honey's own data essentially confirms it. Yet at the same time, the data also confirms that when push came to shove, Honey would eventually bend the knee and remove coupon codes at a brand's request, proving they knowingly misled consumers. Talk about a cluster. [snorts]
Now, if there's one thing people hate more than deception, it's theft. And in my first video, I showed you how Honey was stealing money from influencers. But what I didn't tell you is that this behavior is in most cases strictly not allowed. You see, the companies that run this industry, the affiliate networks, know full well that coupon extensions like Honey, have a high probability of poaching commissions from influencers, bloggers, and other content-driven affiliates. More importantly, they also understand that this is not fair, especially under the last click wins policy, which has remained an [music] industry standard. So, to prevent this type of commission theft, most major affiliate networks enforce what's known as a standdown policy.
Let me show you what that looks like on Honey. Let's visit newe.com first without an affiliate link. And as you can see, Honey immediately pops up offering cash back. But if we do this again, this time using my affiliate link for Newegg, you'll notice that Honey doesn't pop up at all. And if we click on the Honey icon, you can see that Honey is now disabled. So that's how Honey is supposed to behave when a user's already clicked on someone else's affiliate link. So where then is the alleged fraud, you ask? Well, as it turns out, Honey has always had a standown system built into their app, but they have been selectively choosing when and whom to apply the rules.
Let's test my affiliate link for Newegg again. Only this time, I have two entirely separate Chrome browsers open at the same time, and each is logged into a different Honey account. The Honey account on the left has zero cash back points, while the Honey account on the right has accumulated cash back points. Now, watch what happens when I open the Newegg affiliate link on both browsers. The Honey account on the left stands down as it did the first time. But look at this. The account on the right, which has cashback points, did not stand down. So, why is that? Why on earth would Honey act compliant for one user account while violating standown policies for the other? Well, that right there is the fraud. And once you understand why this happens, you'll be shocked at just how calculated and insidious this behavior is.
But before we unpack exactly what's going on here, it's important we first understand how Honey standown system is designed to work. So, here we have Honey standown rules which are loaded onto your computer when you install the extension. At first glance, this might look awfully complex, but it's actually very straightforward. These here are affiliate link patterns for different affiliate networks. Once Honey detects a user has clicked an affiliate link that matches any of the patterns in this list, Honey should in theory stand down. Now, if we go back to my Newegg affiliate link, you can see it says click.linksergy.com linksergy.com and all my other recruitin links have the exact same pattern. Looking at Honey standown rules, we can find that link synergy pattern in the list. Above the link patterns, you'll notice the label provider. This simply tells Honey which affiliate network the pattern belongs to. For example, LS refers to Linkshare, which is now owned by Recruitin. AW is for the AI network, CJ for Commission Junction, etc., etc. And below, Honey defines a timer for how long they should stand down for that affiliate link. And right now, it's set to 3,600 seconds, which is exactly 1 hour. So, if you click on my Newegg affiliate link in the morning, but only complete the purchase later in the afternoon, the standown timer will have expired and Honey will reactivate itself the moment you get to the checkout page. Now, this alone is already a major red flag because I have not seen a single affiliate network specify that standown should only last one hour. So, it appears as though Honey made up this arbitrary rule entirely themselves.
But here's where this gets even more concerning. These standown rules are not hardcoded directly into Honey's extension. Instead, they are stored in the cloud on Honey servers, which you can access through this URL. and the Honey app installed on your computer checks for updates to these rules every hour. Now, that's a very suspicious setup because standown rules are not something that should require frequent updating. But since Honey is refreshing them hourly, it means that a Honey developer could quietly make changes to the standown rules right now. And within an hour, all 20 million Honey users, pardon me, 14 million Honey users would automatically have the new rules. The fact Honey can alter their behavior like this on the fly without any updates or transparency is very concerning. In fact, I was able to find an archive of these rules on the way back machine from 2023. [music] And back then, Honey was only standing down for 360 seconds, [music] which is 6 minutes, mate. It takes me more than 6 minutes to type in my credit card details. So, when exactly did these rules change? Why did these rules change? Did Honey lengthen their standown window after my video came out and the lawsuit started rolling in? I can only speculate, [music] but it certainly seems possible. Either way, Honey's current 1-hour policy is already questionable, but 6 minutes that was blatantly non-compliant and would have undoubtedly resulted in thousands of sales being poached from other affiliates.
Now, as bad as this already looks, you'd think that Honey's standown process would end here. They detect an affiliate link, they stand down. Period. End of story. But unfortunately, that's not the case. Honey takes one more step in the decision-making process, and it's this next step that, in my opinion, constitutes fraudulent behavior. In this next step of the process, Honey essentially goes, "Okay, we've detected an affiliate link, so we know we're supposed to stand down." But standing down means we lose money, and we don't like losing money. So, let's break the rules and ignore standown as much as possible without getting caught. But how exactly does Honey avoid getting caught? Well, the extension starts running tests on your account to determine who you are as a user. Are you A, a legitimate shopper looking for deals, or are you b someone from the affiliate industry testing their extension for compliance? If you're logged in, have an account that's been active for a while, and have already earned a decent amount of cashback points, well, chances are you're a legitimate shopper. At which point, Honey considers it safe to break the rules and ignore Standown. But if you're not logged in or your account is brand new and you haven't earned any cash back points, well now there's a higher chance you're only testing Honey for compliance, in which case Honey plays it safe and [music] stands down.
Now, believe it or not, Honey actually takes this profiling a step further by checking for certain penants in your email address and even examining what websites you visited and what cookies exist on your browser. This is all of course incredibly invasive and I suspect illegal in numerous jurisdictions. But that's exactly the system Honey has created. But don't just take my word for it. Let me show you how the system works. I'll demonstrate it in action and then you can decide for yourself.
So the moment Honey detects an affiliate link from the standown rules before making any decisions, Honey consults this last file called SSD, which I suspect stands for suppress standown or selective standown. Now again, this looks very complex, but it's very straightforward. First, we have these base rules. And the base rules apply to every affiliate link that Honey detects. UL stands for user logged in. And because it's set to one, it means the user must be logged in to Honey. If it were zero, being logged in wouldn't be a requirement. UA stands for user account age, and this rule defines how old your account must be. And right now, it's set to 30 days in milliseconds for whatever reason. Hence the very long number. UP stands for user points and it's currently set to 501. We'll ignore these last two rules for now. I'll explain what those are later. So, the way this works is if your Honey account passes all three of these rules, Honey considers you a legitimate shopper and will [music] not stand down. However, if your account fails any one of these rules, like your account is only 29 days old, Honey considers you too risky and will therefore play it safe and stand down. Honey can also create network specific rules. This ls refers to recruit and links. So for recruiting affiliate links, it now requires that a user must have over 20,000 cashback points. In other words, these original base rules still apply to recruitin links except [music] for the original points threshold, which has now been increased from 501 points to 20,000 points. Honey can also create store specific rules, which is what we have here. For example, 131 is Honey's store ID for Newegg. And this much longer ID is for NordVPN. So that's the gist of it.
Now, let's see these rules in action. Let's start by clicking this Boohoo man affiliate link, which in theory Honey should stand down for. But as you can see, Honey has ignored standown, and that's because my account has passed all the checks. Now, if you know where to look, we can actually see Honey's decision-making process each time we click on an affiliate link. Let's visit another A1 link. As expected, Honey ignores the standown rule again. But notice here how it says SSD. That's the extension confirming that it was supposed to stand down for this link, but didn't because my account passed all of these rules. But what happens if we fail one of these rules? Let's click on this Recruitin affiliate link. Since recruiting links require 20,000 points and my account only has 10,000 this time my account is going to fail Honey's engagement test. And sure enough, Honey stands down for this link. And as you can see here, Honey confirms which rule my account failed, which was the 20,000 user point requirement. But what if we click on this new egg link, which is also on the Recruiter network, but has a store specific rule for 10,000 points. Well, remember store specific rules take priority over network rules. Therefore, Honey ignores standown as my account now meets the required points for this link. Let's do one more for good measure. This time, NordVPN, which has a store specific rule requiring an account age of 8 years. As you can see, Honey stands down because my account is only 8 months old, not [music] 8 years.
So, now that you understand how the system works, it's important to note that I slightly customize these rules to more clearly demonstrate how the system behaves. The actual rules, which I'll show you in a moment, are actually much less strict. This customization was necessary because I wanted to clearly illustrate what happens when my account both passes and fails Honey's checks, especially since my account already has a high number of points and is 8 months old. To use these rules, I made a very basic modification to Honey's extension, telling it, "Hey, instead of grabbing these rules from Honey's server, load these custom rules from my computer instead." [music]
So, what did the actual rules look like? Well, again, thanks to the Wayback Machine, we have one archive of these rules from 2023. And honestly, it's pretty shocking. Looking at the base rules, we can see there were no requirements to be logged in at all, no minimum account age, and no cashback points threshold. whatsoever. Honey only ran these checks on Recruitin affiliate links. I suspect this is because besides being an affiliate network, Routin also has its own coupon cashback extension. [music] So, Routin earns money from Honey as a network, but also has a competing product. So, naturally, they are more incentivized to ensure that Honey is following the rules. It's aed up industry, I know. Besides that, Honey sets store specific rules for the following brands: TTMX, Booking.com, Chaos Sports, The Udie, and the Calming Blanket, likely indicating that Honey received complaints or compliance concerns from these companies. Interesting. So, as you can see, these rules paint a seriously troubling picture. Under these conditions, Honey would have been ignoring standown rules a lot, like in the vast majority of cases, which is insane.
Now, you might be thinking, what is even the point of having this selective standown system if Honey was ignoring the rules virtually all the time? [gasps] Well, that's where this next sneaky rule called GCA comes in. At first, I honestly didn't really understand what this GCA rule was for. It seems somewhat random, but there were several confusing elements in these rules. For example, there was also this random list of URLs, four affiliate network websites, and Swag Bucks, one of Honey's competitors. But why? And then there's this random array of cryptic values with absolutely no meaning behind them. Like, what on earth is conti? At the time, I honestly had no idea at all, so labeled most of it a mystery. But eventually I figured out that GCA, the URLs, and these random values were all connected. And I discovered this by complete accident. You see, one day I was testing a new feature on my own extension. And this feature allows you to see what cookies are being loaded onto your browser in real time as you visit different websites. Now, as I was testing this feature, I logged into my CJ affiliate account, and that's when I noticed a familiar name pop up in the cookie list, K ID. So, I quickly jumped back to the SSD rules to make sure I wasn't going crazy. And there it was, contain name. That's when I realized these weren't random values at all. They were cookies. At that point, I also noticed there were exactly five URLs and five cookies. The first URL in the list is CJ.com, and the first cookie in the list was cont. So, I wondered, were these two lists somehow connected and in [music] order? If they were, that would mean that if I logged into, say, my Awin affiliate account, I should see a cookie named network group load into my browser. So, I quickly logged into my Awin affiliate account, and there it was, Network Group. Another cookie from Honey's list. At this point, I'm thinking, what the is Honey secretly monitoring cookies from these affiliate networks? And if so, why? These cookies have absolutely nothing to do with Honey Service.
But then it dawned on me, the moment Honey detects any of these cookies on your browser, that's the perfect signal for them to know whether you've visited or logged into an affiliate network. And that's significant because, well, let's be honest, no ordinary shopper casually visits affiliate networks like CJ or AIDN, right? I'm sure most of you have never even heard of these companies. So, the only people logging into those sites are Honey's competitors, partnered merchants, and of course, the affiliate networks themselves. Basically, all the high-risisk users Honey desperately wants to hide their shady behavior from. So, the moment Honey detects any of these cookies on your browser, they immediately know you're a high-risisk user and can alter their behavior accordingly. To confirm my suspicion, I quickly loaded up a clean browser with no trace of me visiting any of these networks. I clicked on an affiliate link that Honey typically ignores standown rules for. And as expected, Honey did not stand down. Then in a new tab, I logged into my CJ affiliate account, waited for the Cont ID cookie to load in my browser. There it is. Then opened the same affiliate link, and boom. Now all of a sudden, Honey is acting compliant and is standing down. Holy PayPal, that is not a good look. And once Honey finds this Commission Junction cookie on your browser or any of the others in this list, it does not matter what affiliate link you click on, Honey will not break the rules. Period. And if we check Honey's reporting for why it stood down, it reports back GCA. So that's what the GCA rule is for. It's Honey's kill switch for when it knows you visited or logged into an affiliate network's website. Makes sense.
Now, believe it or not, Honey doesn't stop there. They run two more checks, both of which are tied to the rule labeled BL. First, Honey scans your email address for the word test. If it detects it, Honey immediately switches to compliant behavior. Clearly, another safeguard against compliance testers, which is not a good look at all. And finally, Honey has what appears to be a master kill switch, which is controlled directly from their server via this URL. If the switch says okay, the SSD system remains activated. But if it says alive, Honey switches to full compliance mode. This allows Honey to instantly disable the entire SSD system with a simple flip of a switch from their server.
So, as you can see, Honey put a lot of thought into the system, and I have to say that discovering the logic behind these last two rules was a huge holy moment for me, because it really made the intent behind the system very clear. But before we dive deeper into my thoughts on this, first, let's look at what the SSD rules are right now. As you can see, PayPal has quietly stepped in and added a whopping 65,000 point requirement under the base rules. Now, I imagine that only a tiny percentage of Honey users have acquired 65,000 lifetime points. So, PayPal has effectively limited how often Honey engages in this questionable behavior, which explains why Honey's standown behavior has changed so drastically. In other words, this change wasn't just an update, it was PayPal's attempt at a cover up.
Now, I did briefly consider going on an insane shopping spree to earn those 65,000 points, you know, purely to demonstrate Honey system without using any [music] modifications. But then I realized whoever made the changes to these rules made a critical error. They accidentally left behind a network specific rule for recruiting links, lowering the points threshold to just 5,000 points, much more manageable than 65,000. This oversight was exactly what I needed, a chance to expose Honey's illicit behavior using their own untouched, publicly available extension and rules. So, I went on a painfully expensive shopping spree, targeting products with the highest cash back rates. And sure enough, the moment my account crossed the 5,000 points threshold, Honey immediately stopped standing down on Recruit's affiliate links. At this point, I was fully convinced that Honey was and technically still is engaging in fraudulent behavior.
Looking at the full picture, the implications of what I had uncovered were enormous. This wasn't just some policy violation or shady growth hack, this looked like a Fortune 500 company systematically stealing money from tens of thousands of people while trying to hide it. And given I'm not a software engineer nor a security researcher, it only felt fitting that I consult with a real expert. So, I reached out to Ben Adelman, a respected security researcher known for exposing major online ad fraud, deceptive software, and anti-competitive practices at large tech firms. Ben has four Harvard degrees. He's a lawyer, a software engineer, and a former Harvard Business School professor. But what makes Ben truly unique is that he has a deep decadesl long understanding of the affiliate industry, which is rare. So, I really couldn't have asked for a better person to independently verify my findings. And thankfully, Ben agreed. So, we jumped on a call. I shared my findings. Ben conducted his own test and then we had this interview.
Now that you've had the the chance to go away and you know do your own research, uh were you able to replicate my findings? And if so, you know, how would you characterize the the purpose of the system um that Honey implemented into their browser extension? Your findings are on target. Uh Honey stands down, but only sometimes. Uh and the sometimes is predictable. It's a little different from anything I've ever seen in my whole career testing this stuff, frankly, uh because of the nature of when they stand down and when they don't. They're not doing it randomly. They're not picking a number out of a hat. They're doing it based on articulable factors that we can see in the code, we can see in the packet log, and we can even infer their intent based on what we see there. >> Right. Okay. So you you would agree that this system is fraudulent in nature, specifically that the system was intended to defraud other affiliates and also hide that behavior from uh compliance testers and others within the affiliate industry. >> Well, lawyers have a special view of the word fraud. I'm not sure I'm going to call it fraud myself. Um but it certainly is intended to conceal. They are [music] attempting to stand down as little as possible while avoid avoiding getting caught. Uh those objectives are intention of course. The more you don't stand down, the more you're likely to get caught for not standing down. So they're trying to figure out in what circumstances can they avoid standing down [music] uh and not face a material risk of being caught. >> What do you think the implications are of this? uh you know once this video goes live and I've you know everyone sees and understands the system how do you think the affiliate networks respond? [music] A program that detects testers and hides from testers is incredibly frustrating. It indicates bad faith in the testing process. Not making yourself available for testing. Look, the network should be angry. Uh as to whether they will be angry, you know, maybe it's a little bit tricky for them. Honey is a big partner. It's making them lots of money. uh but they should be angry based on the facts. Anyone who has a application under test that is hiding from the test uh they should be angry about that.
Now Ben also played a key role in exposing one of the largest affiliate fraud cases in history where two individuals went to jail for defrauding eBay of millions of dollars. So naturally I was curious whether he thought this could also lead to criminal charges. >> Criminal charges for corporate misconduct are pretty unusual in the United States. [music] Uh not unprecedented. Uh Volkswagen is an obvious example and there are plenty of other corporations that have ended up in criminal litigation. I wouldn't expect that. I'd expect civil litigation. Uh but if if I were in charge, yeah, this kind of misconduct where you intentionally falsify the results that professional testers [music] get in order to advance your business benefits. Uh looks like a violation of I don't know, it's wire fraud, right? [music] Uh and misrepresentation over the wires. Uh Honey would say, "Well, we didn't misrepresent anything. the wires correctly represented what actually happened. We changed our behavior depending on what was happening that didn't misrepresent it over the wires. I don't know. They misrepresented that funds were payable to them when in fact funds were payable to other people or maybe not at all. Uh [music] so I I charge it on a wire fraud statute, but I don't hold my breath about that. And how high functioning is law enforcement right now? You know, the FBI lost a lot of talented people uh over the past couple years. And so I don't presume [music] that there are technical staff who are able to do this work. A lot has to break right for there to be criminal liability for these violations.
I really have to thank Ben for his time here. Having someone with his level of technical expertise confirm my findings was immensely valuable. Not just for me, but I think for everyone following this investigation. Ben will be publishing his own in-depth research into the system on his blog. So I highly recommend checking that out. I'll link it below.
So, now that we've established what the system is, that leaves [music] us with one last critical question. How long has this been going on for? Was the system developed under PayPal's leadership or under the leadership of Ryan Hudson and George Ruan? I knew the best way to find out would be to locate as many historic versions of Honey's extension as possible and to sift through each version's code. And thankfully, I found almost 300 archives dating all the way back to 2014. Nice. So, I started methodically checking each version one by one, looking for any mention of the SSD rules in the code and found references dating all the way back to version 13.1.0, which was released in March of 2021. Now, keep in mind, PayPal acquired Honey in 2020. So, I was initially under the impression that the system was developed under PayPal's leadership. That was until I stumbled across an article written in 2020 by security researcher Vladimir Pelant. As I read through his research on Honey, this one section stood out where he found that Honey was encrypting specific chunks of their code to conceal it from outsiders. And in one of the screenshots showing this encrypted data, I noticed something familiar, a reference to SSD. I thought, "Holy is this the same SSD? Was Honey originally encrypting the code behind the system to conceal it from outsiders? Well, thanks to Vladimir's expertise, he was able to decrypt this data and shared a portion of the code in his article. And what do you know? Another familiar name shows up, K ID, and a reference to the CJ affiliate network. At this point, I'm confident he had found the same SSD system. The only issue was that Vladimir only shared a small portion of the decrypted code. But thankfully, the URL to this encrypted data was still active and Vladimir included instructions on how to decrypt it. W in the chat for Vladimir. So, I downloaded the code, decrypted it, and sure enough, it was the same SSD system. It checked if you were logged in, how old your account was, if you had over 500 cashback points, whether your email contained the word test in it, and of course, the classic, do you have any affiliate network cookies in your browser?
Armed with this critical insight, I expanded my search and traced the system all the way back to version 10.5.2, 2, which was released in October of 2017, suggesting the system was engineered while Honey was under the leadership of Ryan Hudson and George Ruan and has been around for a staggering 8 years. Now, with that said, it's important we clarify a couple of things. First, these archives were sourced from a third party site called CRX for Chrome. And while I have no reason to doubt their authenticity, it's important to acknowledge the possibility of inaccuracies. Second, none of this serves as proof that Ryan and George were directly responsible for the creation of the system. However, it is difficult to imagine that such a sophisticated system could be developed by some rogue developer without George and Ryan's knowledge. And if we consider who would be most incentivized to develop such a system, well, it would certainly be the two individuals who stood to benefit the most, right? But again, at this stage, we can only speculate. And for that reason, I genuinely hope this triggers an investigation by regulators or law enforcement. The public, the YouTube community, and the entire affiliate marketing industry deserve clear answers.
Now, the next few weeks are about to get very, very interesting because once this video goes live, every major affiliate network is going to have to confront PayPal about the system. And unless PayPal can give them a legitimate business reason for evading standown rules and trying to hide it from them, which I seriously doubt, I honestly think that the affiliate networks will have no choice but to terminate their partnership with Honey. They won't want to. Honey makes the networks a lot of money, but keeping them as a publisher after this. It isn't just risky, it's a potential PR disaster. The severity of the misconduct here is just too high. Even if you put aside the possibility of wire fraud charges, let's not overlook the fact that Honey has been snooping around your browser for cookies entirely unrelated to their service. I cannot stress enough how significant a privacy violation like that is. These are all factors [music] the networks will have to weigh carefully when making their decision.
Now, I'll be leaving a link below with access to the honey files so you can review the data yourself, and I highly encourage you to do so. I'll also include a separate, more technical video that dives deeper into my testing processes and the technical nuances of Honey's system. This should be particularly useful for security researchers, lawyers, and of course, the affiliate networks. There's also a backup of Honey store data on the way back machine. So, I'd like to thank the archive team for helping me facilitate that. And of course, a big thanks to archive.org for providing such a valuable platform. Finally, if you have any information about this system, particularly regarding who was involved in its creation, please feel free to reach out to me anonymously via Signal or Proton Mail. And just to set expectations, uh, part 3 is coming, but it is a massive project and the story is still unfolding in real time with all the ongoing class action lawsuits. I suspect part three will require a lot of travel and coordination, and I'm currently a one-man team doing all of this myself. But in the meantime, I look forward to Ryan's follow-up AMA on Reddit. [music] >> [music] [music] [music] [music]