Absorb the Pirates
When a fraudulent clone steals your users, ship its best features instead of fighting its code
- Difficulty
- Moderate
- Time to result
- ~weeks to results
- Steps
- 4
- Confidence
- 90%
Gojek faced fraudulent third-party driver apps that hijacked its platform, stole driver credentials and threatened to drain driver funds. The engineering-correct response — code obfuscation, API security — was unaffordable given scarce security talent. So Gojek read the pirate apps as free product research, copied their top two or three features into the official driver app, and drained their user base. Treat a successful pirate as a revealed-preference signal, not just a threat.
Origin
Improvised at Gojek out of necessity, not principle — Aluwi is explicit that this was not a philosophical decision but a response to Southeast Asia's extreme scarcity of engineering and security talent at the time. Recounted by Aluwi after Crystal Widjaja reminded him of it.
Core principles
- 01A pirate app with real users is not just an attack — it is a spec of the features your users want and you refused to build.
- 02Users adopt something unsafe only because it delivers value you're withholding.
- 03When you can't afford the technical defence, remove the reason to defect.
- 04Copy the features, not the fraud — retain your safety rationale where it genuinely matters.
- 05This is a necessity play, not a principle. Own that.
How to run it
- 1
Assume adoption means value, and go find it
Instead of asking how the clone is breaking in, ask why users are choosing it. Enumerate what it does that your official app doesn't.
Watch out Don't conflate the fraud vector with the value vector. Gojek's pirates stole driver and financial details — genuinely dangerous — AND offered auto-accept of orders, which drivers genuinely wanted.
- 2
Price the technical defence honestly
Estimate what real security hardening (code obfuscation, API security) would take in engineer-months and whether you have that talent. If the answer is no, stop pretending it's the plan.
- 3
Take the top two or three features and ship them
Don't clone everything. Rank the pirate's features by what's actually pulling users across, take the top two or three, and build them into the official app.
Pro tip Revisit the product rule that created the gap. Gojek had insisted drivers tap 'accept order' manually to keep them conscious of the app; the pirates auto-accepted. The rule was defensible but was costing more than it earned.
- 4
Measure defection, and reopen the security path when you can afford it
Track how many users return to the official app. Feature parity buys you time, not immunity — build the real security investment once talent allows.
Watch out Feature-copying alone leaves the underlying vulnerability open. It is a bridge, not a fix.
In the wild
Before Gojek had invested in code obfuscation and API security, third-party driver apps connected to its platform. They stole driver details, including financial details, with the potential to drain driver funds. But they also shipped features Gojek deliberately withheld — most notably automatically accepting orders the moment they arrived, where Gojek forced drivers to press accept manually to stay conscious of the app. Gojek lacked the security engineers to lock the platform down, so it copied the pirates' top two or three features into its own driver app.
→ The number of drivers using the third-party apps fell significantly, without Gojek building the security system it couldn't staff.
Common mistakes
Reading a clone purely as an attack surface
The fraudulent apps were also providing genuine value to the drivers using them. A team that only sees a security incident never harvests the product intelligence sitting in the clone's feature list.
Committing to a defence you cannot staff
Gojek had no bandwidth for code obfuscation and API hardening — engineering and security talent was extremely scarce in Southeast Asia. Choosing the technically correct path you can't execute leaves users on the unsafe app for longer.
Mistaking the bridge for the destination
Copying features drained the pirates' users but the platform was still open. Aluwi frames the whole move as necessity, not principle — the security investment eventually had to happen anyway.
Is it for you?
Best for
Platform teams facing unauthorised third-party clients or grey-market clones that users actively prefer, with no security engineering headroom to shut them down
Not ideal for
Cases where the clone offers no legitimate feature value (pure credential phishing), or where regulatory/safety exposure makes feature parity itself unlawful
From the transcript
“we ended up making the decision of actually copying those features”
“we just said hey let's take their top two or three features and let's build them into our app and that actually significantly reduced uh…”
“that wasn't a philosophical decision uh or or a principle decision it's actually a decision made out of necessity”
From the episode
Taxi mafias, cash vaults, and 100% MoM growth: The story behind Southeast Asia’s biggest startup
Kevin Aluwi (Gojek)