Every API6 attack succeeded because the API never asked: “Is this activity consistent with legitimate human use of this business flow?”
Not “is this request valid?” — it was. Not “is the user authenticated?” — they were. Specifically: is this actor behaving in a way that our business model intended this flow to support?