A ticketing platform allows: browse events → select seats → add to cart → enter payment → confirm purchase. Tickets are scarce — a sold-out venue with 10,000 seats.
The API has no per-account ticket limit, no minimum time between add-to-cart and purchase, no limit on simultaneous cart holds per session, and no CAPTCHA or human verification step.
Valid accounts. Valid tokens. Valid requests. No rate limit violated. No authentication failure. From a pure security perspective, nothing was wrong. From a business perspective, 10,000 real fans were excluded from a purchase they had every right to make.