Aug 17, 2026

The rigged win: what bots really cost skill gaming

The Rigged Win — what bots really cost skill gaming. THNDR.

A federal court just put a $729 million number on undisclosed bots. The bigger bill lands on every operator and provider that never used one.

Papaya Gaming, maker of Solitaire Cash, filed for Chapter 15 protection after a $719 million disgorgement order in the Southern District of New York. Largest false advertising award on record. It is also the least interesting fact in the case.

Read Judge Denise Cote's findings and a different number jumps off the page. Between 2021 and 2024, 6.1 million people entered at least one tournament where a tailored bot was designed to hand them a loss. And 7.3 million people entered at least one tournament where a tailored bot was designed to hand them a win.

Sit with the second number. It is larger than the first.

Everyone understands why an operator would rig a loss. Rigging a win is the part that should make the whole category uncomfortable, because it has nothing to do with taking a player's money in that moment and everything to do with keeping them. A manufactured victory is a retention mechanic, but it entirely interferes with the skill nature of the games.

That is the story. Not the $729 million.

What the court actually found

Papaya says it discontinued the practice in December 2023 and has said it will appeal. Nothing below is allegation. These are findings from the trial record and the final judgment, plus figures Papaya itself disclosed in its Chapter 15 filings.

  • Tournaments run, 2021 to 2024 — 2.6 billion
  • Tournaments containing tailored bots — 630 million+, roughly one quarter
  • Bot "participants" — 13 million+
  • Human players — 11 million
  • People given at least one engineered loss — 6.1 million+
  • People given at least one engineered win — 7.3 million+
  • Share of cash tournaments with bots, January 2021 — 90%
  • Prizes advertised — $6.7 billion
  • Prizes the court found players actually received — $2 billion
  • Jury award, April 2026 — $420 million
  • Final judgment, July 2026 — $729,213,615.60

The jury returned its verdict on 23 April 2026 at $420 million in actual damages. Judge Cote then substituted disgorgement, which is why the final number is larger: $719 million in unjust profits, plus $10,144,354.04 in fees, $69,261.56 in costs, and interest. The claims were false advertising and unfair competition under the Lanham Act, alongside New York General Business Law claims.

The judgment is not the whole exposure. Papaya settled a US consumer class action, Barcelo et al. v. Papaya Gaming, for $15 million. The Michigan Gaming Control Board issued it a cease and desist letter in October 2024. Papaya's Chapter 15 papers additionally disclose a state attorney general investigation into its past use of automated opponents. Papaya has said it will appeal to the Second Circuit.

Two details make the rest of this piece necessary.

The first is that Papaya has publicly reported annual revenue at around $500 million, with 1 million daily active users, 4 million monthly active users, and 15 million tournaments a day, most of it generated in the US. The filings also confirm that revenue is primarily the spread between entry fees and prizes paid out.

Hold those two facts together. Revenue is the gap between what comes in and what goes back out. Bots "won" $4.7 billion of advertised prizes. The bots were not a growth hack sitting next to the business model. In the periods the court examined, they were inside it.

The second detail: none of this surfaced until Skillz caught it. Evidence then eventually came out of discovery in competitor litigation. The same route the AviaGames allegations took, in a patent case that ended in a $42.9 million jury verdict in February 2024 and a settlement reported at around $80 million. Twice now, in three years, the mechanism that exposed synthetic opponents in real-money skill games was a rival paying third party researcher firms and lawyers to spot the bots.

Bots are not the same thing as AI opponents

The argument against bots gets muddy fast, usually on purpose, so it is worth being precise about what is actually objectionable.

Full disclosure: THNDR in no way, shape, or form utilizes bots or AI opponents. It is my personal opinion that AI opponents are acceptable, however, such use is not in line with THNDR's business practices.

Automation is not the problem. A computer opponent is one of the oldest ideas in games. Chess engines, tutorial bots, practice modes, and single-player AI have made games better for 50 years. Nobody is arguing that a solitaire app should not have a robot to play against.

There are three distinct factors when using opponent automation, and only one is defensible.

  1. Disclosed automation. The player knows they are playing software. This is fine, always, everywhere. It is a feature. Label it and ship it.
  2. Undisclosed automation in paid competition. The player has staked money on the belief that they are competing against another person, and they are not. This is a misrepresentation of the product the player bought. Whether the bot is beatable is beside the point. The player did not purchase a fair fight against a machine. They purchased a fair fight against a human, and the platform sold them something else.
  3. Outcome-tailored automation in paid competition. The house inserts the opponent and configures the result. At this point the word "skill" has stopped describing anything. The player's decisions are an input to an outcome the operator already selected.

Papaya's conduct, as the court found it, falls into the third category. Once synthetic opponents are in the matchmaking pool without disclosure, tuning them is a configuration change. There is no engineering wall between "we filled an empty seat" and "we filled an empty seat with a predetermined result." There is only a policy someone chose to follow, invisibly, forever.

You cannot audit an intention. You can only audit an absence. And again, all of THNDR's play is entirely head-to-head with real, human players.

Why bots exist in the first place

Contrary to popular belief, skill gaming's bot problem is not a morality problem, it's actually an engineering problem that some companies solved with fraud.

A real-money, head-to-head game has a brutal cold start. I know, because we lived it. To seat a match you need another human, at the same stake, in the same game, at a similar skill level, right now. At 2am on a Tuesday in a new lobby, that human does not exist. So the player waits. Then the player leaves. And in this situation everyone loses.

Every honest description of skill gaming has to start there, because that is the pressure that produces bots. A bot solves the cold start instantly and for free. It fills the seat, kills the wait, makes the lobby look alive on day one, and lets a company report matchmaking performance that a real network takes years to earn. And it also gives the company the leg up as the 'house'.

We solved this by creating our cross-operator, matchmaking infrastructure and therefore, we don't need to rely on bots. Just because we do it this way, doesn't make it bible. However, it behooves us as the 'skill gaming industry' to develop a category-level agreement rather than a set of private virtues that still protects players and the integrity of play.

What bots do to a skill game, structurally

Skill gaming exists as a distinct regulatory category, or lack thereof, because of a specific legal and conceptual claim: the outcome is determined predominantly by the participants' skill rather than by chance.

Undisclosed synthetic opponents do not bend that claim. They void it.

If the operator supplies the opponent, the operator controls the distribution of outcomes. A game where the house sets the opponent's performance is a house game. It might have a solitaire UI on it, but the money mechanics are the money mechanics of a slot machine with extra steps and none of the disclosure obligations that slot machines carry.

When a court, a state attorney general, or a legislature examines an operator that used tailored bots, they are not just examining that operator. They are testing whether the phrase "game of skill" describes anything reliably skillful. Every skill-gaming carve-out, every legal opinion an operator relies on, every regulator conversation that starts from "this is not gambling, here is why" gets harder in proportion to how many times the sentence turns out to have been false.

Using bots not only defrauds an operator's own players, but it genuinely spends credibility it did not own, borrowed from every competitor who built the hard version.

The case for a disclosure norm

I will stop bitching and propose a solution:

Synthetic opponents should be avoided in paid skill competition, and where any automation exists in a product, it should be disclosed before or at the point where the player commits money.

Two things follow from that, none of which require a regulator to mandate them.

  1. Disclosure before payment. If a player can be matched against software, they should be told before they pay, in the same screen where they pay. If a company believes its automation is acceptable, it should have no difficulty saying so out loud.
  2. Verifiability instead of assurance. Every operator that later turned out to use bots also said it did not use bots. Users, partners, and regulators should be able to check: verifiable game records, replays a player can watch, identity and behavioral verification on the accounts in the pool, and matchmaking logic that can be inspected rather than described.

Neither of these are hard.

This is also the work in front of the Online Skill Gaming Committee at the International Gaming Standards Association, whose charter explicitly covers matchmaking transparency and opponent-matching algorithms that are "fair, transparent, auditable, and clearly disclosed to participants."

How you actually fill a lobby without bots

Everything above is easy to say. The part that earns the right to say it is solving the cold start honestly, so here is what that looks like in practice.

  • Pool liquidity across operators, not within one. Cross-operator liquidity is how we've decided to solve the problem at THNDR. It is super fucking hard, but the work compounds: every operator that joins makes fill faster for all of them, and every real match sharpens matchmaking, fraud detection, and game design. We welcome others to tap into our network with their content. Shoot me a DM to discuss.
  • Change the format so a simultaneous opponent is not required. Head-to-head is the format that creates the cold start. Tournaments with many entrants, asynchronous scoring, and 1vMany structures need players in a window, not players in the same second.
  • Verify the humans you do have. Game verification, replays a player can watch after the fact, and skill-proofs make each result checkable. This is also the only honest way to make the no-bots claim, because it is the version someone else can test.
  • Design the economics so real players stay. A 50/50 target win rate and skill brackets keep whales and grinders from draining the prize pool and driving casual players out. An operator that lets its best players farm everyone else will end up with an empty lobby and will feel the same pull toward filling it artificially.

At THNDR, we have 99.99% fill rate across 160m+ games played, running real-money skill tournaments for iGaming operators at scale since 2019, with 25 partners live.

Note that it is 99.99% and not 100%.

That 0.01% is the most important digit in this entire post. A network of real, paying, verified humans will occasionally fail to seat a match, because real people are not infinitely available. The remainder is what honesty looks like in a metric. If a supplier's numbers have no remainder, ask where it went.

What operators should ask every skill games supplier

While standards are being formulated, this is diligence any operator can run when speaking with a potential skill games provider:

  1. Can a player in a paid contest ever be matched against software? Yes or no.
  2. If yes, where is that disclosed, and is it disclosed before the player pays?
  3. Has the product ever used automated opponents? When did it stop, and what changed technically to make it stop?
  4. Can I inspect a completed match independently? Show me a replay.
  5. What verification runs on accounts in the matchmaking pool?
  6. What is the fill rate, and what accounts for the portion that does not fill?
  7. Who is accountable if a regulator asks these questions after we have launched, and what does the contract say about it?

These are super simple questions that can be taken care of on Day 1.

Don't play the waiting game

Papaya is still operating after filing Chapter 15. They are running at full capacity in a supervised payment arrangement rather than a shutdown, and it expects the appeal to take years. This is precisely why the industry should not wait for the market to sort this out.

Skill gaming has a genuinely good argument to make. Players competing against players, outcomes determined by decisions, an operator earning a service fee for running a fair contest rather than winning when the player loses. This is a powerful argument, but it truly only holds if the companies operating in the space adhere to a collective framework of what this looks like.

This is what we are working on with the International Gaming Standards Association, but we welcome conversation with anyone in the space on how to confront the use of bots and responsible disclosures with automated agents.

The Skillz v. Papaya saga may be coming to an end, but players were the real victims left with little to no recourse. It's still early for skill gaming and we can collectively set out to grow with integrity.

CEO and Co-founder

Des Dickerson