Security and scaling

Referral Rewards in a Drama App Without Fake Accounts

By the GetFame team Published 12 min read

Short answer

Stop fake accounts by tying the referral reward to a qualifying action, not to sign-up, and by layering controls: a small reward, a per-referrer cap, a hold before payout, one-time claim rules and ledger monitoring. No control stops every cheat. The aim is to make farming cost more than it pays and to reverse what slips through.

Key takeaways

  • Paying at sign-up rewards the cheapest action to fake, so pay after a first unlock or purchase wherever you can.
  • The common farming patterns are self-referral, many accounts on few devices and emulator installs, and each leaves a different trace in the ledger.
  • Use layers: small rewards, caps per referrer, a payout delay, claim limits, rate limiting and a staff routine to hold, review and reverse.
  • Keep referral rewards in coins, not cash, so a farmed reward costs inventory and cannot be withdrawn.
  • Store rules target rewards for ratings, reviews and installing other apps, so never tie a referral reward to those.
On this page 10 sections
  1. How referral loops get farmed
  2. Pay on a qualifying action
  3. Reward design and the cost of fakes
  4. Control layers
  5. Monthly reward limits
  6. Watching the ledger
  7. Handling a farmed account
  8. Store and network rules
  9. Which campaign brought which purchase
  10. What to decide next

A referral program pays existing viewers to bring in new ones, and anything that pays for sign-ups will be farmed. The fix is not a single clever check. It is a design: reward a real action instead of a sign-up, keep the reward small and in coins, limit how much one referrer can earn, wait before paying, and read the ledger often enough to see a ring forming. This post is that design for a drama app.

Our white-label ShortMax clone ships a referral loop paid in coins, with a code per viewer and a referral history on both clients. This guide sits beside daily check-in rewards and rewarded ads for free episodes, because the same viewer wallet pays all three and the same abuse patterns reach all three.

How referral loops get farmed

Know the patterns before you design the controls. Each one has a different cost for the attacker and leaves a different trace.

PatternHow it worksWhat you see
Self-referralOne person makes a second account with their own code, often with a throwaway emailReferrer and invited account share a device, network or sign-up time
Device farmsMany accounts created on a small number of real phones, sometimes a rack of cheap devicesDozens of new accounts per device, each claiming the sign-up credit and little else
Emulator installsVirtual devices create accounts by scriptPerfectly regular timing, identical device models, no real viewing
Referral ringsA group invites each other in a loopChains where A invites B, B invites C, C invites A
Disposable identitiesThrowaway emails or recycled numbers pass a simple checkMany accounts from the same email provider with random names
Code postingCodes posted on public boards so strangers claim themOne referrer with hundreds of invitees and no social link between them

None of these needs skill. All of them rely on one design flaw: the reward is paid for an action that costs the attacker almost nothing. That is the first thing to change.

Why it matters beyond coins

A farmed account is more than a lost coin. It inflates your install and sign-up numbers, so your marketing reads better than it is. It skews the retention figures you use to decide what to fund. And if farmed accounts also watch rewarded ads for coins, the ad traffic starts to look like invalid activity, which AdMob treats seriously (see the rules section below). The cost of a ring is a distorted business, not just a few coins.

Pay on a qualifying action

The most effective control is the trigger. Decide which action proves the invited person is a real viewer, and pay only after it.

TriggerCost to fakeReal-viewer frictionNotes
Sign-upAlmost nothingNoneThe shipped credit in our platform lands here
Verified emailLow (throwaway addresses)SmallStops typos, not farms
First unlockLow to medium (free reward coins can pay for it)NoneProves the viewer reached the lock
Return on a later dayMedium (needs a second session)NoneProves a second visit
First purchase that clearsHigh (needs real money)Delays the rewardStrongest. Reversal of the payment can reverse the reward

Be exact about what our platform does. The referrer is credited when a friend signs up with their code, in an amount you set in the fourth reward tab, and the referral history screen shows who joined. Moving the trigger to a first unlock, a return visit or a first purchase is a change to the referral flow that we make for your build, with timelines typically in the 2 to 8 week range; confirm scope with us at kickoff. Until then, the controls below carry the load, and the reward amount should be small enough that sign-up farming is not worth the effort.

One detail to settle at delivery is the guest identity. Our build lets a first visit begin without an account and collects rewards on a durable guest identity, which helps the first coin land. It also makes a cheap account. Decide whether a guest can earn or trigger a referral credit before registering, or whether the credit waits for a registered sign-in. Holding referral credits for registered accounts is the stricter choice, and it is something to agree with us when a ShortMax clone script is configured for your market.

Plan the wording on screen as well. "Invite a friend. You earn coins when they watch their first episode" is honest and cuts farming. "Get coins for every friend who joins" invites volume over quality.

Reward design and the cost of fakes

A referral reward is paid in coins you issue, so a new viewer costs you inventory and not cash. That is a large advantage, because a farmed reward cannot be withdrawn. Viewer cash-out is something we can set up for your build, with payout rails built to your market. Keep it out of the referral loop unless you are ready for a much larger fraud problem.

The reward should sit below what a new viewer is worth to you, and it should stay worth less than a purchased coin. A worked example with invented round numbers shows how fakes inflate the real price of a customer.

  • Say the referral reward is 100 coins with a face value of 1.00.
  • Say 1,000 sign-ups arrive through referral codes in a month, and 400 of them are fake.
  • You issue 100,000 coins, which is 1,000.00 at face value, to get 600 real viewers.
  • That is about 167 coins, or 1.67, per real viewer, against a nominal 1.00, a 67% rise.
  • If a few referrers produce most of the fakes, a cap of 20 referrals a month limits each referrer to 2,000 coins, which is 20.00 at face value.

The percentages are illustrations, not measurements. The shape is the lesson: a fake share of 40% raises your real cost by two thirds, and a cap on each referrer places a hard ceiling on one bad actor. For how acquisition cost fits the wider model, see the ShortMax clone business model page.

One-sided or two-sided rewards

Our shipped credit goes to the referrer. A reward for the invited viewer as well is a design some operators prefer, because it gives the friend a reason to accept the invite. It also doubles the payout on a fake pair, so add it only together with a qualifying-action trigger, and treat it as a scoped change.

Control layers

No single control is enough. Stack them so that defeating one still leaves the others. The status column says what the platform provides and what we set up for your build.

ControlWhat it stopsFriction for real viewersStatus in our platform
Small coin rewardMakes farming poor valueNoneAmount set in the console
One-time claims for bonusesRepeating email, social and login bonusesNoneIncluded
Daily caps on ad tasks and check-inUnlimited claims per accountNoneIncluded
Per-referrer capOne referrer collecting a ring's rewardOnly the heaviest invitersSet up for your build
Payout delay or holdInstant cash-in-and-leaveA short waitSet up with the qualifying-action change
Qualifying-action triggerSign-up-only farmsReward arrives laterSet up for your build
Sign-in method rulesThrowaway guest identitiesSome friction at first visitFive sign-in types, including guest entry; choose which can trigger a credit during delivery
Request rate limitingScripted bursts on login, check-in and unlockNoneAvailable; we set it up for your build
Device and emulator checksMany accounts per device, virtual devicesRare false positivesAvailable; we set it up for your build or connect an outside provider
Wallet inspection, balance adjustment, blockLetting a farmed reward standNone until it is neededIncluded for staff, with named roles

The honest summary is that the platform gives you claim limits and the staff tools to review and reverse, and we set up the stronger layers (a different trigger, caps per referrer, device checks) for your build. Rate limiting matters most for check-in and referral endpoints, so agree it with us before go-live.

Monthly reward limits

A budget is the last backstop. If everything else fails, a ceiling on what referrals can issue in a month bounds the damage. Our console sets values and caps per source and does not impose one monthly total across all rewards, so you hold the total by arithmetic and by checking the ledger.

  1. Pick a monthly ceiling for referral coins, as a share of all reward coins and as a number.
  2. Multiply expected sign-ups by the reward amount to see the expected spend, then add a margin for a bad month.
  3. Set a tripwire at about half the ceiling and read the ledger when you pass it.
  4. If a push or a promotion would exceed the ceiling, lower the reward for its length instead of letting it run.

Keep the ceiling in line with the wider reward budget in the check-in post, since the same reward balance is spent first and the same expiry window applies to referral coins.

Watching the ledger

The typed ledger gives referral credits their own code, so you can read them apart from check-ins, ads, purchases and unlocks. A farm usually shows in the ledger before it shows anywhere else.

  • Spikes by referrer. One referrer with a sudden run of credits, far above the typical count.
  • Clusters of new accounts. Many accounts created in a short window, with regular spacing, all invited by a few codes.
  • Same-device and same-network patterns. Several accounts on one device or address. Device fingerprinting is something we can set up for your build, or you can use your own server logs or an outside provider.
  • No viewing after the credit. Invited accounts that claim a bonus and never reach a locked episode. Quality, not volume, is what to read in the referral history.
  • Chains and loops. A invited B, B invited C, C invited A.
  • Balance shapes. Wallets that receive only credits and never spend.
  • Purchase rate by source. Referred viewers who never buy are a cost, not growth.

Review these weekly in the first months of a referral push and after every campaign. The more precise reads, such as a cohort table of referred against organic viewers, are something we can set up for your build, on top of the operational counts and ledger views the platform already gives you. For the metrics themselves, see retention metrics for creator platforms.

Handling a farmed account

You will find one. Decide the routine before you do, so a bad week does not turn into a bad policy.

  1. Hold. Mark the suspect account and stop further claims. Blocking an account is a console action.
  2. Review. Open the wallet and the history. Check whether the coins were spent or are still held.
  3. Reverse. Adjust the balance to remove the coins that came from the abuse. There is no automatic clawback, so each reversal is a staff decision. Write down the reason.
  4. Tell the viewer. Send a short message through the inbox. Say what you found and how to appeal.
  5. Close the gap. Ask what let it through and which layer would have stopped it.

Your terms must say what happens to coins from accounts you block for abuse. Without that sentence, a reversal reads as theft. Allow for honest cases: two people in one household can use one device and one network, and a friend group on one campus can look like a ring. Review before you block. The general approach to false accounts on a platform, including identity checks and review queues, is covered in fake profiles on dating apps, and the wider ledger discipline in how a coin economy works.

Store and network rules

The platform rules are narrower than many operators assume. We read the pages below, as of October 2026, and they can change, so read the live versions.

SourceWhat it says (summarized)What it means for referrals
Apple guideline 3.2.2(x)Apps must not force users to rate or review the app, download other apps or take other store actions to access functionality. Apps may incentivize actions inside the app.A reward for a friend joining your service is an in-app action. Do not require a rating, review or other-app download for a reward.
Same page, 5.6.3Manipulating elements of the App Store experience, such as charts, search, reviews or referrals to your app, is not permitted.Do not use rewards to push your store ranking, and do not run rewarded-review schemes.
Google Play: ratings, reviews and installsDevelopers must not inflate ratings, reviews or installs through incentivized reviews and ratings, or by incentivizing users to install other apps as the app's main functionality. The key-considerations list says not to offer rewards for ratings or reviews.Never tie a referral reward to a Play rating or review. Keep the invite about using your service.
AdMob invalid trafficAutomated clicking tools and repeated clicks or impressions by one or more users count as invalid activity.Farmed accounts that watch rewarded ads can look like invalid traffic and put your ad account at risk.

None of the store pages we read describes a ban on paying a viewer coins for inviting a friend to a service, and they do not address your market's own consumer or marketing law. Keep the invite honest, disclose the reward, and ask each store's review team if your flow is unusual. This is not legal advice, and messaging and incentive rules differ by country.

As for named apps, we read the ReelShort App Store listing and the ShortMax listing as of October 2026. Neither describes an invite program in its published text, so we make no claim about whether either offers one.

Which campaign brought which purchase

Once referrals work, you will want to know which source produced buyers. The referral history shows who joined through whose code, and the campaign desk reports delivery figures for each send. That is not attribution. UTM tracking, deep linking, install attribution and A/B testing are available from us if you need them, set up for your build.

Until you add them, use what you have:

  • Use a separate promotional referral amount during a push, so a window of high credits is visible in the ledger.
  • Schedule one campaign at a time and compare purchases in the days after each.
  • Read referred viewers' unlocks and purchases against organic viewers from the same weeks.

An attribution provider can be wired through the referral and campaign surfaces by us. Ask for it when your volume justifies the added cost.

What to decide next

  1. Choose the action that proves a real viewer, and plan the change from sign-up if you need it.
  2. Set a small reward, in coins, below the value of a new viewer.
  3. Decide whether the invited viewer is rewarded too, and add it only with a stronger trigger.
  4. Scope the layers you want on top of the base: per-referrer cap, payout hold, rate limiting and device checks.
  5. Write the terms: what happens to coins from blocked accounts, and how to appeal.
  6. Agree who reviews the referral ledger each week and what counts as a reason to hold, review or reverse.

The ShortMax clone features page lists the referral loop, the wallet tools and the claim limits as shipped, and the ShortMax clone development cost page explains the scope, and we confirm the exact scope for your build at kickoff (contact us). Start with a small program, read it for a month, and widen it only when the ledger shows real viewers.

Questions and answers

Can fake accounts be stopped completely?

No. A determined person can always create another account. The goal is to raise the cost of farming above the reward, to catch patterns quickly and to reverse what slips through. Pay on a first unlock or purchase, cap rewards per referrer, delay payout and watch the ledger. Treat each control as a layer, never as a guarantee.

How long should rewards be held before payout?

Long enough for fraud signals to appear and short enough that real friends still feel rewarded. A few days is a common starting range, and your own data should move it. Tie the hold to the qualifying action, such as a first purchase that clears, so a reversed payment also reverses the reward.

Which login methods help against fake accounts?

Methods that tie an account to something harder to mass-produce, such as a verified email or a social login, raise the cost of farming compared with a bare guest identity. Our platform supports five sign-in types including guest entry. Decide during delivery which ones can trigger a referral credit, and read the abuse trade-off against first-visit friction.

Can I reverse a referral reward?

Yes, as a staff action. In our platform staff can open a viewer wallet and history, adjust a balance and block an account. There is no automatic clawback rule, so write your policy into the terms first, saying what happens to coins from accounts you block for abuse. Record the reason each time so you can answer an appeal.

Do I need an outside messaging service for referrals?

Not to start. The referral screen gives each viewer a code and a history, and the campaign desk can announce a referral push through in-app inbox rows without a third-party service. Device push runs on your own Firebase project. Install attribution and deep links are something we set up for your build.

Do app stores allow rewards for inviting friends?

The pages we read target manipulated ratings, reviews and chart rankings, forced store actions, and incentives to install other apps. Apple also lists referrals to your app among elements that must not be manipulated. Do not link rewards to a rating, a review or another app's install, and check the current store pages before you submit.

Sources

  1. Apple App Review Guidelines (3.2.2, 5.6.3)
  2. Google Play Console Help: User ratings, reviews and installs
  3. Google AdMob Help: Invalid traffic
  4. Google AdMob Help: Policies for ad units that offer rewards
  5. App Store listing: ReelShort - Stream Drama & TV
  6. App Store listing: ShortMax - Short Dramas & TV

Checked in October 2026. Rules, fees and programme terms change; confirm on the source before you rely on them.

Independence note. GetFame is an independent software company. ShortMax is a trademark of its owner and is named here only to describe a category of platform. GetFame is not affiliated with, sponsored by or endorsed by ShortMax.

ShortMax guides All articles

→Start here

Tell us what you want to launch.

Share the platform and your market. You get a walkthrough of the live demo, the exact scope of what ships, and a fixed price in writing. First response in under 2 hours, Monday to Saturday, 10:00 to 19:00 IST.

We reply to every inquiry. No newsletters, no shared data. See our privacy policy.