All resources
Case study · Reebok × Alien: Romulus

Aliens vs Bots: the Reebok Stomper drop

A checkout-flow flaw let cook groups and bot operators push orders through before the midnight launch — taking the majority of the limited-edition sneakers in the process.

When Reebok announced its latest collaboration with the Alien movie franchise — a fresh take on the OG Bug Stompers — loyal customers, botters, and resellers all bought into the hype, circling midnight on August 27th on their calendars. Unfortunately, a flaw in the checkout flow allowed cook group members, and later bot operators, to sneak orders through the system before launch, taking the majority of the limited-edition sneakers in the process.

Why it matters

Bot operators, cook groups, and resellers have become increasingly sophisticated, at times outpacing traditional blue-team defenses. While corporate security teams have rightly prioritized protecting against malicious threats and fraud, an additional class of challenges is emerging — one that directly affects customer experience and revenue streams.

More than another drop in the bucket

Sneaker drops are historically highly anticipated, with price tags and resell value double or triple typical prices, making them ripe for botting. The Air Jordan 1 is considered the first real limited-edition sneaker drop. Although it released in 1985, before the internet was widely available, the marketing campaign designed around the shoe is considered one of the greatest to date. When Michael Jordan was banned from wearing his namesake sneaker by the NBA, the hype exploded, and the fines Nike paid paled in comparison to the money the company raked in as a result.

Now, botters look for any release that fits a similar pattern: scarce product, plenty of hype — evidenced by online chatter and PR — and proof from past events that resale value will be high. After successfully producing multiple limited-edition iterations of the Stomper in 2016, 2017, and 2019, the door was open for Reebok to capitalize on the franchise once more with Alien: Romulus. Writer/director Fede Álvarez told GQ, “I couldn’t resist, and we reached out to Reebok to ask them to be part of this one and give us a new set of sneakers for a new generation.”

Zoom in: how did the sneakers get scooped?

  • As hype built — fueled by coverage like a GQ feature — multiple cook groups began strategizing for the drop. In the days beforehand, members started generating hundreds of accounts on Reebok’s site, anticipating that account registration would be required to complete a purchase.
  • One group identified a method to check out prior to the release date and time, then provided guidance to their users through a tutorial video.
  • The method leveraged parameter tampering between the client and server, substituting an already-carted item’s variant with the restricted item’s variant. Once the Stompers were carted, they could complete their purchases.
  • To avoid raising alarms on the Reebok side, cook group members waited until the final hour before the drop to begin checking out, hoping to reduce the number of merchant cancellations.
  • At the same time, a retail botting-software vendor built a Reebok module for the event, released to its users in the final minutes. Some users were surprised to see their tasks checking out early — the module inadvertently took advantage of the same parameter-tampering flaw — and equally shocked to see that the majority of inventory had already been scooped by the other cook group.

What did fans say?

The 140-plus reviews that accumulated on the since-removed product page in the aftermath of the Romulus release said it all. Fans were furious.

Lessons learned

From a broader perspective, Reebok’s experience mirrors trends seen across other retailers. Vesal Security has identified consistent patterns of similar issues affecting multiple vendors, highlighting an industry-wide challenge with Customer Experience Security.

  • Security teams should be an integral part of the Customer Experience strategy — not only monitoring transaction flows on high-demand products, but setting up defenses before a release and monitoring during the event.
  • Customer account creation is expected in the lead-up to a drop, but security teams must work within the Customer Experience team to continuously monitor and validate controls against automated account creation — preventing abuse while keeping onboarding smooth for legitimate users.
  • A quick sell-out does not always mean the campaign was a success. Strong feedback loops exist on the product page in customer reviews, and within support chat and call logs post-drop.

Prove your controls hold.

Bring us a live promotion. We'll show you how it stands up to the real adversary. No deck. No discovery call.