Inventory Hoarding is a form of automated abuse in which bots are used to place items into shopping carts, hold reservations, or otherwise lock up available inventory – often without ever completing a purchase – depriving legitimate customers of access to those goods. It is sometimes called “inventory denial” or “denial of inventory,” because its effect can be to make products appear sold out or unavailable to real shoppers even though no genuine sale has occurred. It is a business-logic abuse: the bots use the site’s legitimate cart-and-checkout functionality, but in a way and at a scale never intended.
The mechanics typically involve bots rapidly adding high-demand or limited-stock items to carts and holding them there, exploiting the common e-commerce behavior of reserving inventory once an item is in a cart (to prevent overselling). By holding large quantities in carts, attackers can effectively remove that stock from circulation for the duration of the hold. Depending on intent, they may release it later, complete purchases selectively (as in scalping), or simply cause disruption.
Motivations vary. Scalpers hoard scarce, in-demand items – limited sneakers, concert tickets, gaming consoles, high-demand electronics – to buy them up and resell at inflated prices, using hoarding to secure the stock before genuine customers can. Competitors may hoard a rival’s inventory to frustrate that rival’s customers and damage sales and reputation. In all cases, real customers are blocked, seeing items as unavailable and abandoning the site frustrated.
The harm to businesses includes lost or distorted sales, frustrated and alienated customers, skewed inventory and analytics data, and reputational damage – particularly around high-profile product launches where hoarding and scalping are rampant. It also erodes fairness, as bots outpace humans in competing for limited goods.
Because inventory hoarding uses legitimate functionality, it evades tools that inspect individual requests for technical maliciousness – each cart addition looks normal. Defenses draw on bot management and business-logic protection: detecting automated behavior through behavioral analysis and fingerprinting, rate limiting cart actions, imposing sensible cart hold times and quantity limits, requiring authentication or challenges for high-demand items, monitoring for abnormal add-to-cart patterns, and applying anti-bot measures during product launches. As with other automated business-flow abuses, effective defense depends on distinguishing genuine human shopping from coordinated automation.