Yesterday evening, while working on a client project, I noticed an unusual number of issues coming through Sentry.At first, I ignored them. But they kept coming.Eventually, I checked Vercel and saw around 1,500 visits to aveiro.app with no clear traffic source.
That was unusual. Aveiro does not normally receive anything close to that amount of traffic in a few hours.Then I opened Stripe.It showed almost $6,000 in new MRR, but $0 in actual revenue.There seemed to be only one realistic explanation.
The obvious explanation
We recently created a custom F6S deal offering an extended two-month trial on Aveiro's Starter and Creator plans. I checked the F6S dashboard, and the code had only been revealed there by around 40 people.So this traffic clearly was not coming from the community the deal had been designed for.Someone must have found the code and started exploiting the platform.Maybe they were creating trial accounts to resell. Maybe they were trying to drain our AI credits. Maybe it was some automated attack I did not understand yet.The account data appeared to confirm it.There were strange patterns across the email addresses. Some contained words like "hacker." Others looked sequential, with variations ending in ".1," ".2," and ".3."New accounts kept appearing. They were consuming infrastructure, creating sites and using AI credits.Aveiro is a bootstrapped platform. We do not have unlimited resources to spend on hundreds of accounts that appear overnight and look illegitimate.So I reacted.
I stopped it in less than ten minutes
I immediately disabled new registrations.Then I disabled every account associated with the incident, logged them out and cancelled their subscriptions in Stripe.The entire response took less than ten minutes. The attack was stopped.Except something still did not make sense.Who was behind it? What were they trying to achieve? And why were so many of the accounts actually using the product?
I kept digging.
The story did not become clearer. It became more confusing.
Then I opened their sites
At that point, Aveiro did not have a convenient way for me to inspect unpublished customer sites. So I quickly implemented one.
Then I started opening them.
I expected spam, duplicated accounts or empty projects created to claim AI credits.
Instead, I found experiments. Real ones.
People were changing layouts, writing content, generating pages and trying to understand how the platform worked.
There were not just a few convincing examples. There were hundreds.
That was the moment I realized I might have made a serious mistake.
I had just disabled around 460 real people and cancelled all of their Stripe subscriptions.
Reversing everything I could
I immediately switched from defence to damage control.
I reopened the platform.
I restored access to every affected account, removed the restrictions and refilled the AI credits they had lost.
Almost everything could be reversed. One thing could not.
The Stripe subscriptions were already cancelled.
Everyone could continue using the two-month trial, but they would need to set up their subscription again before it ended. They would no longer convert automatically.
That is how I deliberately wiped almost $6,000 in projected MRR from Stripe in less than ten minutes.
But while I was restoring everything, new people kept arriving.
The number started climbing again.
And by the next morning, Stripe looked like this:
$10,786 in MRR.
Still $0 in actual subscription revenue. These people are on an extended trial, and we have no idea how many will eventually pay.
But they are real.
We now know where they came from, why some of the accounts looked so suspicious, and how a single person did more marketing for Aveiro in less than one minute than I may have done in months.