All case studies
Case study

Protecting SMS OTP endpoints from automated abuse

Layered abuse detection for SMS OTP: IP, device, user-agent, phone-number patterns, geography, request signing and rate limits instead of one IP limit.

Context
Production incident on SMS OTP verification (client under NDA)
Role
Backend Tech Lead
Key point
Incident → 7 independent signals
  • Rate limiting
  • Request signing
  • Redis
  • SMS OTP provider

The problem

A production incident: our SMS OTP endpoint was being abused (OTP pumping), repeatedly triggering verification messages and running up cost.

The existing protection was essentially a single IP-based limit, which is easy to get around.

Architecture: before → after

Before
  1. OTP request
  2. IP rate limit
  3. Send SMS
After
  1. IP
  2. Device
  3. User-Agent
  4. Phone-number pattern
  5. Geo restriction
  6. Signed request
  7. Rate limit
  8. Send SMS

What I did

  • Combined several independent signals: IP, device, user-agent and phone-number patterns.
  • Added geographic restrictions for regions the product does not serve.
  • Required authenticated / signed API requests before an OTP can be sent.
  • Applied rate limits across those signals rather than per IP only.

How I led it

  • Treated it as an incident: investigated request logs and SMS billing to find the abuse patterns and the root cause.
  • Proposed the fix as independent layers: geo restriction, rate limiting and API key / request signing.
  • Communicated the cause and the proposed fix to the stakeholders involved.

Outcome

  • Abuse protection no longer relies on a single IP-based limit.
  • Each layer can be tuned or tightened independently.