Every credit card number carries a built-in error detector invented in the 1950s. It won't tell you a card is real — but it'll catch the typo before you ever hit the payment network.
Type a credit card number into a checkout with one digit wrong and, more often than not, the form flags it instantly — before anything talks to a bank. That's not magic and it's not a database lookup. It's a checksum baked into the number itself, designed in the 1950s, still doing its job on billions of cards. Understanding it demystifies a small but everywhere-present piece of infrastructure, and it clears up a dangerous misconception about what "valid card number" actually means.
What the Luhn algorithm is
The formula has a name and a clear purpose. Wikipedia describes it:
"The Luhn algorithm or Luhn formula, also known as the 'modulus 10' or 'mod 10' algorithm, is a simple check digit formula used to validate a variety of identification numbers."
— Wikipedia, "Luhn algorithm" (CC BY-SA 4.0)
It's a check digit scheme: the last digit of the number is calculated from the others, so a computer can instantly test whether the whole thing is internally consistent. Card numbers use it, and so do IMEI numbers on phones and various national ID schemes.
The math, in plain steps
It's genuinely simple. Starting from the rightmost digit and moving left, you double every second digit. If doubling produces a two-digit result (say 8 → 16), you add those digits together (1 + 6 = 7) — or equivalently subtract 9. Then you sum every digit (the doubled-and-adjusted ones plus the untouched ones). If that total is divisible by 10, the number passes. The final digit of the card is chosen precisely so the sum comes out to a multiple of 10 — that's the "modulus 10" in the name. No cryptography, no lookup table, just doubling and adding.
Which errors it catches
The design target was human data-entry mistakes, and it's well matched to them. Luhn catches every single-digit error — get any one digit wrong and the checksum fails. It also catches most adjacent transpositions, the very common slip of swapping two neighbouring digits (typing 21 as 12). Between those two, it detects the large majority of the mistakes people actually make keying in a long number. For a scheme this cheap to compute, that's an excellent hit rate — which is why it has survived seventy years essentially unchanged.
The error it misses
No simple checksum catches everything, and knowing the gap matters. Luhn's notable blind spot is the transposition of 09 and 90 — swapping those particular digits happens to leave the checksum unchanged, so it slips through. There are a handful of other twin-digit transpositions it can't distinguish. This isn't a flaw so much as the price of simplicity: a check digit is a cheap filter, not a guarantee. It's meant to catch the common typos at zero cost, not to be tamper-proof.
"Passes Luhn" is not "is a real card"
Here's the misconception worth killing. Passing the Luhn check means only that the number is internally consistent — the digits add up correctly. It says nothing about whether the card exists, belongs to anyone, has funds, or hasn't expired. You can generate Luhn-valid numbers all day that correspond to no real account. So Luhn is the right tool for one job — catching typos on the client side before you bother the payment network — and completely the wrong tool for "is this a legitimate card?", which only the issuer, through the actual payment authorization, can answer. Treat a Luhn pass as "worth submitting," never as "verified."
Check it, and know its limits
Use it for exactly what it's good at. A credit card validator runs the Luhn check (and identifies the card network from the prefix) so you can catch a mistyped number instantly — a great client-side check that saves a doomed round-trip. To appreciate that Luhn is a checksum and not a security measure, contrast it with a real one-way function in a hash generator: a hash is built to resist tampering; Luhn is built only to catch honest slips. And when you're writing the input handling around a card field — stripping spaces, matching the digit pattern before you even run Luhn — a regex tester helps you get that pattern right. A 1954 checksum still guarding modern payments is a nice reminder that the best infrastructure is often the simplest.
← All articles