Cloudflare is known to use fingerprinting to detect scrapers For example, they use JA3 fingerprints and match them against the UA to block stuff like cURL while allowing OkHttp (Android clients) - but this can be easily be spoofed with packages such as CycleTLS [1]. I don't want to defend them, because they gate away a good chunk of the internet with their "bot protection", but unless you do PoW (which is also ecolog…
This is why I have two separate browsers. If you want to do official stuff like paying for things you need to get through cloudflare.
(That said, I still keep separate machines. One for doing "official" things, the other for everything else)