Coupon Extensions and the Last-Click Credit Grab

By Juan Carlos Herrera ·

Illustration: Coupon Extensions and the Last-Click Credit Grab

You click a creator’s referral link, browse for a while, then a coupon-hunting browser extension pops up at checkout and searches for a discount code. It doesn’t find one — no code applies, no savings appear — and you pay full price. Nothing about that feels like it should matter to anyone but you. But behind the scenes, opening that popup can be the moment the sale stops being credited to the person whose link brought you there and starts being credited to the extension instead. Understanding why requires understanding how “credit” gets assigned online in the first place.

What last-click attribution actually is

Almost every referral and affiliate system uses some version of last-click attribution: whoever’s tracking link was the most recent one to touch your browser before you completed the purchase gets the commission. Not the first link you clicked. Not the site that actually convinced you to buy. The last one.

Mechanically, this runs on cookies (or, increasingly, other browser storage). Click a tracking link and the merchant’s site — or an affiliate network sitting in front of it — drops a small file that says “this visitor arrived via Creator X, dated today.” That cookie usually has a shelf life measured in hours to months, called the attribution window. If you check out before it expires and no other tracking link has landed on top of it in the meantime, Creator X gets paid. If a second tracking link touches your browser first, the second one wins. The cookie doesn’t stack; it overwrites.

That overwrite rule is completely ordinary when it happens between two creators competing honestly for the same click. It becomes a different story when the thing doing the overwriting is a tool that was never in the room when you decided to buy.

How a coupon extension can insert itself without your knowledge

The consumer-facing pitch of a shopping/coupon browser extension is simple: it watches for a checkout page, tests a library of codes against the cart, and tells you if any of them save money. Millions of people run one for exactly that reason, and when a working code applies, most people are glad the extension found it.

The part that doesn’t show up in the pitch is what a class-action lawsuit against PayPal’s Honey extension alleges happened underneath that popup. According to the consolidated complaint — In re PayPal Honey Browser Extension Litigation, filed in the U.S. District Court for the Northern District of California (case no. 5:24-cv-09470) — when a shopper clicked “Apply Coupon,” the extension allegedly opened a hidden browser tab that loaded a URL carrying Honey’s own affiliate identifier, deleting whatever creator’s tracking cookie was already sitting in the browser and replacing it with the extension’s own. The complaint describes this happening even when the extension found no working code and even when a shopper only dismissed the popup without applying anything — the mere act of the extension running its check was, allegedly, enough to fire the swap. More than two dozen creators and publishers, consolidated under the caption Wendover Productions v. PayPal, allege this diverted commissions that had already been earned by the referral or affiliate link that actually brought the shopper to the site. A federal judge declined to dismiss the case in June 2026, and it’s now in discovery — meaning the underlying facts about how the extension behaved are still being litigated, not settled.

The mechanism being alleged has a name in advertising law: cookie stuffing — dropping a tracking cookie on a browser without the user meaningfully initiating the transaction that’s supposed to earn it. It’s routinely banned by the terms of the affiliate networks and merchant programs that referral and affiliate links run through, which is precisely why it’s the center of the lawsuit rather than a described feature.

It’s worth being precise about what has and hasn’t been established, because the case is ongoing. A motion to dismiss surviving means a court found the creators’ allegations, if proven, would be enough to win — not that the allegations have been proven. PayPal has disputed the characterization of Honey’s mechanics in its defense. Discovery, expert reports, and (if it doesn’t settle first) a trial are still ahead. Treat “Honey allegedly stuffs cookies” as an accurate description of a pending legal claim, not as an adjudicated fact — and treat the broader pattern it describes (a checkout-time extension that can overwrite attribution regardless of whether it helps you) as the thing worth understanding regardless of how this particular case resolves.

What it means for you as the shopper, not the creator

Most coverage of this dispute is written for the people losing commissions — the creators and publishers on the other end of the tracking link. If you’re the shopper clicking “Apply Coupon,” the direct financial stakes are different, but not zero:

  • You don’t lose money either way. Whether the credit lands with the creator’s link or the extension, your price at checkout is the same. Cookie-swapping doesn’t cost you a cent directly.
  • The creator you meant to support might not get credited. If you followed a referral link specifically to support someone — a friend whose invite code you’re using, a creator whose review sent you there — running a checkout-time extension can silently redirect that support to a company you’ve never heard of, without notifying either of you.
  • It complicates “who actually gets paid” transparency. We’ve covered how referral codes, promo codes, and affiliate links differ in who benefits; an extension that can insert itself as the final link in the chain adds an actor to that picture most people never account for.
  • The disclosure question runs in the opposite direction from what you’d expect. The FTC’s Endorsement Guides require anyone recommending a product for pay to disclose that connection to you — see the FTC rules every referral-code sharer ignores for the full breakdown. A checkout extension isn’t recommending anything to you in that sense; it’s acting on a transaction already in motion, on behalf of an economic interest — its own commission — that most users never think to ask whether it discloses.

None of this means shopping extensions are inherently bad, or that you should feel guilty running one. Most of them work exactly as advertised: they check for a code, and if one applies, you save money you wouldn’t have otherwise. The point is narrower — that a tool sitting in your browser at the exact moment attribution gets decided has more leverage over who gets paid than its interface suggests, and that leverage is currently the subject of active federal litigation rather than an established, disclosed fact. If you specifically want a creator’s link to get credit — because you’re using a friend’s invite code, or you followed someone’s referral post — the safest sequence is to complete checkout without opening any coupon-search popup at all, since the credit is decided by whichever tracking link touched your browser last.

If you create content and share referral or affiliate links yourself, the flip side of this story — what publishers are required to disclose, and what your own program terms allow — is covered in our field guide to referral programs vs. affiliate networks.