Switching Between Accounts on One Computer to Farm Invites: How Device Machine Codes and Fingerprints Trigger Linked Bans
Inviting yourself and getting banned across the entire system? A technical deep dive into how Cursor reads the network adapter's physical address, motherboard serial number, and system machine code hash, warning of the joint-liability risk of self-referral and self-purchase.
1. The Technical Flaw in the Clever Trick of Self-Referral and Self-Purchase
Some people, hoping to get rewards for free, use two different email addresses on one computer to send invitations to each other, thinking that if they switch browsers and accounts, the company definitely will not know.
That idea is extremely naive in the face of modern clients.
2. Hardware Probes Built into the Cursor Client
When Cursor runs locally, it reads unique low-level hardware serial numbers and generates machineId and macMachineId.
When the backend data center finds that the client hardware hashes of the invited account and the inviting account match exactly, the system will directly classify it as a Sybil Attack. It will not only withhold any credits, but also directly revoke the main account's referral permissions and even suspend the device.