getting destroyed by free tier abuse and I don't know what to do

Built a social media data API (SocialCrawl) and I’ve been getting hammered by fake signups burning through free credits.

The screenshot is a snippet of what the fake bot accounts look like, all the same disposable email domain. The user in the image created 100 fake accounts and had another user creating 30 fake accounts.

https://preview.redd.it/8c9hjsd7pz8h1.png?width=441&format=png&auto=webp&s=4c822ff3e2f415f5e59fd1dc607c4145497c9857

I want to keep the free tier because it's our best acquisition channel. Removing it is the best option, I know, but want to keep it as the last resort.
I’m going to add captcha on signup and start building more security layers..

Anyone faced similar problems? Have you tried

  • Credit card on free tier (does it nuke conversion)?
  • Rate limiting by IP + email combo?
  • Just accept it as the cost of doing business?

Would love to hear how you guys are handling this type of problem, I need advice!

Thanks!

Author: dooddyman