Operators that let a payout verification prompt sit on screen for more than 90 seconds before a player can clear it are seeing measurable damage to their re-buy rate in the first hour of a session. Internal data from three mid-size US-facing social and sweepstakes casino platforms, covering roughly 4.1 million sessions between January and March 2025, shows that rebuy frequency among players who hit a two-factor payout hold past the 90-second mark fell 17% relative to a matched control cohort whose holds resolved under 30 seconds. The effect held after controlling for stake size, device type, and time of day, which suggests the mechanism is not demographic but friction-driven: the hold interrupts a decision loop that has a short half-life.
The 90-second threshold is not arbitrary
The 90-second figure emerged empirically rather than from a design spec. When the three operators logged time-to-verification against subsequent session behavior, the drop-off curve was flat until roughly 75 seconds, inflected sharply between 80 and 95 seconds, and then flattened again at a lower plateau. That inflection is what the 17% figure describes — the gap between the pre-inflection cohort and the post-inflection cohort, not a linear decay.
This matters because compliance teams often treat any hold under two minutes as "fast." A 110-second hold feels, from the operator's dashboard, like a well-functioning system. From the player's side, it reads as a stall, and the behavioral data suggests the distinction between 85 seconds and 110 seconds is not cosmetic. The cohort that cleared at 88 seconds retained 91.4% of baseline rebuy behavior. The cohort at 104 seconds retained 74.3%.
The mechanism is plausibly attentional. A player mid-session who is asked to retrieve a code from a second device, or wait for an SMS, is being asked to hold an intention across a delay. Intention-holding degrades with time, and around the 90-second mark the cost of continuing starts to exceed the cost of simply closing the tab and doing something else.
Where the friction actually lives
Two-factor authentication is not one thing. The payout holds in this dataset came from four distinct triggers, and they behave differently.
SMS one-time codes
The slowest and most common. Median delivery time across the sample was 34 seconds, but the 90th percentile was 141 seconds — carrier-dependent and, for some prepaid numbers, effectively broken. SMS holds accounted for 61% of all post-90-second events.
Authenticator apps
Median resolution of 22 seconds, with a much tighter distribution. Players who had already enrolled in an authenticator app rarely breached 90 seconds. The problem is enrollment: only 18.7% of the sample had done so.
Email verification links
Slowest of all when it required switching devices, since a meaningful share of players are on mobile and their email client is a second app-switch. Median 47 seconds.
Manual review queues
These are not really two-factor events, but they get bucketed with them in most operator dashboards. Median 14 minutes. Rebuy behavior after a manual review hold is a separate question and probably not recoverable through UX alone.
The 17% headline figure is dominated by SMS and email holds. Strip those out and look only at authenticator-app users, and the rebuy delta drops to roughly 4%, which is within noise.
What the operators changed
One of the three platforms ran a partial intervention starting in February 2025 and the results are the most useful part of the dataset.
They moved the second factor to the front of the session rather than the payout moment. Players who opted in were asked to verify at login, once, and then hold a trusted-device token for 30 days. The hold still existed; it just stopped landing in the middle of a payout decision.
Rebuy behavior for the intervention cohort recovered to 96.8% of baseline — a 13.5-point improvement over the post-90-second control. Payout fraud attempts did not increase materially over the 11-week window, though the sample is too small to make a strong claim about tail risk.
The second change was less obvious: they stopped counting the hold from the moment the prompt appeared and started counting from the moment the player could reasonably act. Under the old metric, a hold that fired while the player was switching apps looked fast on the dashboard and slow in reality. Under the new metric, the same hold looked slow, which triggered an escalation path. Roughly 9% of holds were being misclassified.
The compliance tension
None of this argues against two-factor authentication. Payout fraud is real, chargeback exposure is real, and the regulatory direction in most US states is toward more verification, not less. The question is where the friction sits, not whether it exists.
The uncomfortable finding is that a control that works — that genuinely reduces fraudulent payouts — can still cost more than it saves if it lands at the wrong moment in the player lifecycle. A 17% rebuy reduction on a cohort that represents, in this sample, about 12% of payout-triggering sessions is a meaningful revenue line. Whether it exceeds the fraud losses prevented depends on the operator's chargeback rate, which none of the three platforms would disclose.
There is also a regulatory wrinkle. Some state frameworks require verification at the point of withdrawal rather than at login, which constrains the login-time fix. Operators in those jurisdictions are left optimizing the 90-second window itself: pre-fetching codes, offering authenticator enrollment at signup with an incentive, and routing known-good devices around the prompt entirely.
What is not settled
The 17% figure is real within this sample, but the sample is three operators, one quarter, and a US market where sweepstakes and social casino rules are shifting month to month. It is not clear whether the effect is stable across seasons, whether it holds for sportsbook-style cashout flows, or whether the inflection point moves for players who have been on a platform for years versus days.
The more interesting open question is whether the 90-second threshold is a property of human attention or a property of current device interfaces. If app-switching gets faster — if SMS delivery becomes reliably sub-10-second, if passkeys replace the code entirely — does the inflection point move, or does it stay anchored to something more fundamental about how long a player will hold an intention before abandoning it? Operators building verification flows in 2026 are, whether they frame it this way or not, making a bet on that answer.