I gotta say... this is an incredibly naive analysis. To demonstrate Reddit Ads isn't doing click fraud protection, you should try to generate a fraudulent click yourself. Looking at what is getting through and finding that a lot of it as easily identifiable as fraudulent is NOT a valid signal. It's incredibly likely that there are far more bots that are being blocked and that the bots that are getting through have in…
A company basically did what you described on Facebook, Google, Bing and Yahoo. https://www.methodmi.com/reports/in-plain-sight
That said, this report's objective isn't really to measure click fraud detection on those networks. It's to highlight that one doesn't have to be very sophisticated to commit ad fraud (which is absolutely true). It also has some really odd ideas (e.g. they contacted the Chrome team to let them know about the existence of the stealth plugin in, and were surprised that the Chrome team said that the browser was working as intended so there was no action for them to take on their part... they similarly drew a false equivalence between defending account creation vs. defending click fraud). They also seemed to think that sites should be blocking bots, which is of course not what you want to do, because that provides a feedback loop to the fraudsters so that they can figure out how to overcome the measures. You want to proceed as if it is working, even let it show up in the ad campaign data at least initially, and as much as possible make corrections in ways that make it difficult to determine which traffic has been identified as fraud.