What a 3-D Secure challenge does to a Malaysia-facing checkout
Challenge windows, issuer apps, and a shopper returning on a different network all look like abandonment if the app only listens for a success callback.
Malaysia-facing card traffic still meets 3-D Secure on a large share of attempts. The shopper leaves your webview or in-app browser, opens a bank app or an issuer page, and — if the night is ordinary — comes back. Conversion tracking that only listens for an immediate success callback will file that person as gone.
Two details make the hop worse than a textbook diagram. First, the return may arrive on a different network after the shopper switched from mobile data to Wi-Fi in a mall. Second, the issuer app may keep them longer than your spinner’s patience. If the app records abandonment when the spinner ends, you have invented a quit that the bank never saw.
Record three states: challenge started, challenge returned, challenge timed out. Keep the original intent event so a timeout is not indistinguishable from a shopper who never tapped pay. When we audit Malaysia-facing checkouts, the missing return state is as common as the authorisation-as-sale mistake, and it produces stranger weekly charts because it clusters around evening traffic.
This is not an argument against 3-D Secure. It is an argument against a funnel that has no chair for the shopper who did what the issuer asked.