Founder narrative
Anya Petrova8 min read3 views

The month a chargeback wave froze my Stripe at $23K MRR: a founder diary (2026)

The month I crossed $23K MRR, a card-testing attack slipped a few hundred fraudulent charges past my checkout. Weeks later the disputes rolled in, my dispute rate crossed 0.75%, and my processor froze payouts. A composite founder diary on chargebacks, watchlists, and frozen cash.

Updated on July 24, 2026

Flat editorial illustration of a solo founder at a desk watching a laptop that shows a sharp red spike on a line chart and a padlock over a paused payout bar, on a warm sand background.
Flat editorial illustration of a solo founder at a desk watching a laptop that shows a sharp red spike on a line chart and a padlock over a paused payout bar, on a warm sand background.
In this story
The dashboard just said Payouts paused. No amount, no date, no human. I refreshed it maybe forty times before I accepted it was real.

Quick answer (2026): At $23,000 MRR a card-testing attack slipped a few hundred fraudulent charges past my checkout overnight. Weeks later the real cardholders disputed them, my dispute rate climbed past the 0.75% that the card industry treats as excessive (Stripe, 2026), and my payment processor paused payouts and put me on a fraud watchlist. This is the month I learned that a chargeback wave is not a billing problem, it is a cash-flow emergency, and that the only real defense is friction you add before you need it. Figures here are self-reported and lightly anonymized; this is a composite founder diary, not a single named company.

I had been telling people my SaaS was "boring in a good way." Steady $23K MRR, about 430 paying accounts, churn under control, no drama. I had stopped checking Stripe every morning because there was nothing to check.

Then there was.

The morning the payouts said "paused"

I opened the laptop on a Tuesday and the Stripe Stripe logo dashboard had a gray banner where the green "next payout" line usually sat. Payouts paused. Charges still going through, but the money was not moving to my bank. Below it, a risk review notice and a request for documentation.

My first thought was that I had been hacked. My second, worse thought came a few clicks later when I sorted the payments list by date and saw the shape of it: a dense wall of tiny charges, mostly $1.00 and $2.00, hundreds of them, clustered between 2am and 5am the previous week. Some declined. A frightening number approved.

I had never seen it before, so I did not recognize it for what it was. It has a name, and once you know the name you see it everywhere in founder forums: card testing.

What actually happened: a card-testing attack, then the wave

Card testing is when someone with a list of stolen card numbers runs them through a real checkout in small amounts to see which ones still work (Stripe, 2026). My signup form had a card field and no meaningful friction on it. To a bot, that is a free validation service.

The attack itself was not the disaster. The disaster was the timeline. The bots hit me on a Wednesday night. My processor's automated systems and my own belated rules shut most of it down within a day, and I refunded everything I could find. I thought that was the end of it.

It was the beginning. Over the next three weeks the actual owners of those stolen cards saw the charges, did not recognize my product's name on their statement, and filed disputes. Every refund I had already issued did not matter to those; a dispute is a separate action from the bank's side. They arrived in ones and twos at first, then in a clump.

Here is the part nobody warns you about. Disputes are measured against the payments from the date they were charged, and that window stretches back up to 120 days. So a burst of fraud on one Wednesday keeps poisoning your dispute rate for months as the chargebacks trickle in. My rate went from a healthy 0.2% to about 1.1% over roughly six weeks, even though my legitimate business had not changed at all.

The number that gets you flagged

I did not know any of the thresholds until I was already over them. So, plainly, for the next founder who searches this at 3am:

The credit card industry treats dispute activity above 0.75% as excessive, and a sudden spike can put you into a monitoring program even before you cross that line (Stripe, 2026). Every dispute counts against you whether you win it or lose it. And it is not one rulebook, it is several. Mastercard Mastercard logo puts a merchant into its Excessive Chargeback program at roughly 100 or more disputes in a month at a 1.5% ratio, with fines that start in the second month and escalate from about $1,000 upward the longer you stay in it. Visa Visa logo runs its own acquirer monitoring with an excessive ratio around 1.5% in the US (Stripe monitoring programs, 2026).

At $23K MRR, a $1,000 monthly fine is not a rounding error. It is a chunk of my own salary. And the fine is the small part. The real threat sitting under all of it is the sentence every processor's terms reserve: if you cannot get the numbers back in line, they can stop processing your payments. For a business whose entire revenue runs through one pipe, that is not a fine, that is the off switch.

The 11 days I spent getting off the watchlist

I want to be honest about how unglamorous the fix was. There was no clever hack. It was eleven days of grinding through a checklist while trying not to spiral.

First, I stopped the bleeding at the front door. I added rate limiting on the payment endpoint so no single IP could try more than a handful of times. I turned on the processor's built-in fraud rules and set them aggressive, accepting that I would block a few real customers rather than let another bot wave through. I put a challenge in front of the checkout for anything that smelled automated.

Second, I fought the disputes I could actually win, and conceded the ones I could not. For the fraudulent charges, I stopped submitting evidence entirely. You cannot win a dispute on a genuinely stolen card, and fighting them just wastes the flat dispute fee, which was about $15 each in my case, win or lose. I accepted those and focused my evidence on the small number of real-customer disputes where I had logs, delivery, and usage to show.

Third, I got the rate down by growing the clean denominator. This is the counterintuitive lever. Dispute rate is disputes divided by payments. My fraud numerator was fixed and decaying out over the 120-day window; I could not un-file a chargeback. But every clean, legitimate payment I processed made the ratio smaller. So keeping the business running normally, and not panic-pausing my own signups, was itself part of the cure.

Fourth, I over-communicated. I replied to the risk review with a plain-English writeup: here is what happened, here is the attack pattern, here are the exact mitigations I shipped with timestamps, here is the trendline coming back down. I did not argue. I gave them a reason to believe the spike was an event, not a business model.

Payouts resumed on day 11. I got the dispute rate back under 0.75% in about six weeks as the poisoned window aged out. It felt less like winning and more like the tide going back out.

What it cost, in money and in nerves

The direct cost was ugly but survivable. Roughly $18,000 of my own money sat frozen in transit for those eleven days, which for a solopreneur running on a thin buffer meant I very nearly could not make payroll for the one contractor I had. If you have read the month I almost ran out of cash at $17K MRR, you know I did not have much cushion to begin with. The dispute fees and the refunds together ran to a few thousand dollars. The processor did not fine me in the end, because I got the numbers back before the escalation months hit.

The real cost was the two weeks I spent unable to think about anything else. I did no product work. I answered support slowly. I lay awake doing dispute-rate math. The business was fine the whole time in every way that mattered to customers, and none of them noticed, and I still nearly broke.

There is a strange sibling relationship between this month and the month involuntary churn from failed payments hit me at $28K MRR. Both were payment-plumbing problems that never showed up in my feature roadmap or my marketing, and both hurt more than any competitor ever did. The boring layer is where the real risk lives.

The one thing I would tell past me

Add the friction before you need it, and watch the trendline, not the total.

I had treated my checkout's fraud settings as a someday problem because I had never been attacked. That is exactly the wrong instinct. Card testing does not scale with your success; a bot does not know or care that you are only doing $23K MRR. The cost of turning on rate limiting and aggressive fraud rules on day one is a handful of false declines. The cost of turning them on after an attack is your payouts, your focus, and a couple of weeks of your life.

And keep a cash buffer that assumes your processor could freeze you for two weeks with no warning, because it can, and the notice will be a gray banner and nothing else.

Sources

A

Written by

Anya Petrova

Anya Petrova writes first-person founder diaries for OperatorBook, tracing the messy operational reality behind each MRR milestone.

Frequently asked questions

What dispute rate is too high on Stripe in 2026?

The card processing industry treats dispute activity above 0.75% as excessive, and a sudden spike or steep upward trend can put you into a monitoring program even before you reach that line (Stripe, 2026). Every dispute counts whether you win or lose it, and the rate is measured against the payments by their charge date.

Can a card-testing attack get my payment account frozen?

Not usually on the same night. The danger is the delayed chargeback wave: card testing runs stolen cards through your checkout in small amounts, then over the following weeks the real cardholders dispute those charges. That burst of disputes is what pushes your dispute rate up and can trigger a payout freeze or a fraud review.

Why do chargebacks keep coming weeks after I refunded the fraud?

A refund and a dispute are separate actions. Refunding a fraudulent charge does not stop the cardholder's bank from filing a chargeback, and disputes are counted against the date the payment was charged, across a window of up to 120 days. So one night of fraud can keep poisoning your dispute rate for months.

What happens if I hit Mastercard's Excessive Chargeback program?

Mastercard's Excessive Chargeback program starts at roughly 100 or more disputes in a month at about a 1.5% ratio, with fines that begin in the second month and escalate from around $1,000 upward the longer you stay in it (Stripe monitoring programs, 2026). Visa runs a similar acquirer monitoring program. The deeper risk is that a processor can stop handling your payments entirely if you cannot recover.

How do you lower a dispute rate fast?

You cannot remove disputes that already happened. Practically you do three things: stop the source of fraud with rate limiting and aggressive fraud rules, stop wasting money fighting disputes on genuinely stolen cards, and keep processing clean legitimate payments so the ratio's denominator grows while the fraud ages out of the 120-day window.

How much cash should a solo founder keep for a payout freeze?

Enough to run for at least two weeks with zero incoming payouts, because a processor can pause payouts with no warning and the only notice may be a banner in your dashboard. Treat a freeze as a cash-flow event, not a billing dispute, and size your buffer for the frozen amount plus your fixed costs.