All case studies
Case study
Protecting SMS OTP endpoints from automated abuse
Layered abuse detection for SMS OTP: IP, device, user-agent, phone-number patterns, geography, request signing and rate limits instead of one IP limit.
- Context
- Production incident on SMS OTP verification (client under NDA)
- Role
- Backend Tech Lead
- Key point
- Incident → 7 independent signals
- Rate limiting
- Request signing
- Redis
- SMS OTP provider
The problem
A production incident: our SMS OTP endpoint was being abused (OTP pumping), repeatedly triggering verification messages and running up cost.
The existing protection was essentially a single IP-based limit, which is easy to get around.
Architecture: before → after
- OTP request
- IP rate limit
- Send SMS
- IP
- Device
- User-Agent
- Phone-number pattern
- Geo restriction
- Signed request
- Rate limit
- Send SMS
What I did
- Combined several independent signals: IP, device, user-agent and phone-number patterns.
- Added geographic restrictions for regions the product does not serve.
- Required authenticated / signed API requests before an OTP can be sent.
- Applied rate limits across those signals rather than per IP only.
How I led it
- Treated it as an incident: investigated request logs and SMS billing to find the abuse patterns and the root cause.
- Proposed the fix as independent layers: geo restriction, rate limiting and API key / request signing.
- Communicated the cause and the proposed fix to the stakeholders involved.
Outcome
- Abuse protection no longer relies on a single IP-based limit.
- Each layer can be tuned or tightened independently.
More case studies
- Scaling a high-traffic microservices backend on AWS
- Making cache synchronisation resilient with SQS, retries and a DLQ
- A realtime social platform that scales horizontally
- Removing a webhook race condition with database-level idempotency
- Leading delivery decisions under deadline pressure