A client I contract to currently has recently seen an increase in Mapbox usage from a block of IPs which are owned by a hosting company. These IPs haven't managed to get through to the server itself (all the requests are logged as blocked in Cloudflare) but they have been able to use the Mapbox token to request maps.

This has seen their billing go from $4,000 to $60,000 a month. After some back and forth with Mapbox they've provided a list of IPs which all fall within the same IP block and all have over >500,000 map/tile loads per day.

This incident raises concerns about whether any protective measures are available against such abuse. Are organizations utilizing public tokens potentially putting their yearly budgets at risk due to malicious actors?