July 8, 2026
Gift card draining costs shoppers over $1B. See why better packaging won't stop it, and how NFC smart labels remove the secret thieves need.

The gift card looked untouched. Sealed carrier, crisp barcode, hanging on the rack between a hundred identical ones. The shopper bought it, loaded fifty dollars, and mailed it to a nephew. By the time he tried to spend it, the balance was zero. Nobody picked a lock. Nobody forged a signature. The money was gone because the card's secret was sitting in the open, weeks before anyone bought it.
This is gift card draining, and it has quietly become one of the most industrialized retail crimes in North America. The Federal Trade Commission logged more than 41,000 reports of gift and prepaid card fraud in 2024, accounting for roughly $212 million in reported losses, and reported figures are always a fraction of the real total. Investigators tracking the broader scheme put losses above $1 billion over a two-year span, most of it traced to organized crime rather than lone opportunists.
The uncomfortable truth for anyone who issues, manufactures, or sells gift cards: the industry is trying to solve a data problem with physical packaging, and losing.
Every draining technique depends on one thing. The value secret has to be physically present and readable before a customer ever buys the card.
The first method is harvest-and-wait. A crew pulls cards off the rack, records the card number and the scratch-off PIN, then reseals the packaging convincingly and returns the cards to the display. Automated systems poll the balance line until a shopper buys one and loads it. The moment funds land, bots drain the card online, often within minutes.
The second method skips the wait. A criminal covers the real barcode with a sticker carrying their own account's barcode, so the register credits the thief's card at checkout while the customer walks away with a shell. Either way, the crime is complete before the recipient ever unwraps the gift.
The mechanics are cheap, repeatable, and global. One ring dismantled under the Department of Homeland Security's Operation Red Hook was tied to more than $100 million in compromised cards, funneled into electronics that were reshipped overseas. A federal agent on the case described the scale as reaching into the hundreds of millions, potentially billions.
The instinct across the sector has been to make the card harder to reach: tamper-evident carriers, secure tear-strips, hidden or dual barcodes that separate activation data from the spend PIN, scratch-off coatings, and codes applied only at checkout.
These are real improvements, and they raise the effort required. But they share a single structural weakness. They all protect a secret that never changes and that is printed on the card before it ships. Tamper-evident packaging tells you a breach happened; it does not prevent the value from being spent once the static PIN has been copied. Determined crews reseal cards well enough to fool the next shopper. A secret you can photograph, scratch, or clone in advance is a secret that will eventually leak.
Physical hardening is a strong first layer, and it belongs in the stack. It is not the finish line.
Lawmakers have noticed. In 2025, roughly 22 states introduced more than 30 bills targeting gift card fraud, a sharp jump from eight states the year before, with Maryland, New Jersey, and Nebraska enacting rules on secure packaging, point-of-sale warnings, and record-keeping. Federal enforcement through Operation Red Hook has produced convictions and seizures across multiple states.
Regulation is closing in, and that is good news for consumers. But most of these laws mandate better packaging and clearer warnings. They harden the shelf. They do not remove the secret from the shelf. The moment mandatory compliance deadlines arrive, issuers who bolt on one more layer of static defense will simply be meeting the minimum, while the underlying vulnerability stays exactly where it was.
Here is the shift. If draining works because the value secret is printed and readable before purchase, then the fix is not a tougher wrapper. It is refusing to print the secret at all.
That is the model a connected NFC smart label makes possible. Each card carries a cryptographic NFC chip bound to its own identity, so the spend PIN is never printed on the card and never sits in the packaging. A card lifted off the rack has nothing worth harvesting, because the thing the entire scheme depends on is simply not there. The card stays inert until it is legitimately sold, then the customer confirms it by tapping the card with their phone. No app. No download. The reveal happens only on an authenticated tap of an activated card, and every tap produces a new single-use cryptographic proof, so a copied link or a replayed tap reveals nothing.
The result flips the economics of the crime. There is no static PIN to scratch and record. There is nothing to read through the cardboard. There is nothing to clone in advance. Harvest-and-wait dies at the rack, and a swapped-barcode card is exposed the instant a buyer taps and sees it is not active, so it can be flagged before a cent moves.
Related reading: QR Code vs NFC for Brand Protection A printed QR or barcode can be photographed and duplicated in seconds. See why a tap that mints a fresh cryptographic token each time closes the gap that static printed codes leave wide open.
None of this requires reinventing the production floor. ForgeStop's BatchMaker™ links each chip to its card at line speed as cards come off the press, and the NFC inlay is embedded during normal lamination, adding less than 0.3mm and no new applicators. Redemption runs on existing rails, because the PIN was simply never exposed before purchase.
Related reading: How NFC and RFID Are Transforming Asset Tokenization. Every card can carry a unique, verifiable digital identity. See how NFC and RFID turn an ordinary piece of plastic into a tamper-resistant, individually authenticated asset from the moment it is made.
There is a second reason to move the secret onto a chip. That authenticated tap is not only a security checkpoint. It is a branded moment. The same tap that reveals a PIN can show the balance, surface an offer, launch a loyalty flow, or drop the recipient into a fully branded experience served on the brand's own domain. The chip that shuts down fraud also opens a direct, first-party channel to the person holding the card, which is exactly how the added component earns its keep. Protect. Connect. Experience.
For teams evaluating options, the brand-agnostic checklist is short:
Gift card draining is not going away on its own; it is too profitable and too easy. But it is beatable, and not by wrapping the same vulnerable secret in one more layer of plastic. It is beatable by taking the secret off the shelf entirely.
See how ForgeStop's InfoTap® smart labels remove the secret thieves rely on. Request a demo and we'll show you a live drained-proof card, from production line to the tap on a phone.
Sources: National Conference of State Legislatures, "Gift Card Fraud Surges as Scammers Get More Sophisticated," February 2026; Forbes (Steve Weisman), "Gift Card Draining: How Organized Crime Steals Millions From Shoppers," June 2026; Moneywise / Yahoo Finance, "Americans lost $1B to a 'gift card draining' scam," December 2025 (citing Bloomberg and ProPublica).