Active defenses against abuse — captcha, honeypot, rate limits, AI budget.
Proof-of-work captcha (ALTCHA) on auth flows.
Hidden field "bookmark" on the feedback form (2000ms minimum fill time).
Per-IP and per-email limits. Per-email: 5/1 h.
Daily token cap of 100,000 per user.
Think this pattern could be better? Tell us how.