Both patterns exploit the same gap: the API implements the flow correctly but has no business-level controls — no purchase cap, no minimum completion time, no account verification gate, no anomaly detection for machine-speed activity. The API does exactly what it’s supposed to do; the business rules never said “not this fast, not this many times.”