This kind of abuse has always been the main issue for faucets' sustainability. It should be easy and quick to claim from faucets, but due to cheaters, faucet owners have to add different anti-bot mechanisms, which end making the whole process much longer for users.
Another mechanism faucet owners use is to not immediately pay users on every claim directly to their addresses, rather they have to accumulate a minimum balance first until being able to withdraw. This way, you can identify which are legit claims and which are automated ones before paying.
Yes, I was expecting this for sure, but I think with AI it is becoming easier and easier for anyone to code RPAs that can mimic normal user behavior.
You guys must have seen those "mobile farms" where one user controls hundreds of mobile phone screens from one display. If a captcha or robot check appears, the user solves it manually, and then the bot continues the rest.
Look at this username. I sent 50 sats, but come on, at least change the username please.


Although I also think this might be an automatic username generated by Wallet of Satoshi.

Why don't you set up a longer cool down timer or only limits one claim every 24 hours?
100 satoshi is not too much but if the faucet is abused, it can be drained out very quickly.
With people who actually have needs of getting 100 satoshi for experience something, firstly with faucets, and secondly using 100 satoshi for something like fresh try, they will not try to abuse your faucet after that.
In addition, if it is for pure experience like testing knowledge, they can claim testnet bitcoin from testnet faucet and use such coins on the testnet.
I don't want to make it too complicated. Even a 10-minute cooldown timer may not be fair for some users who genuinely want to try Lightning payments.
Yes, testnet is useful, but testnet is still just a test. It does not feel as exciting as holding or sending real bitcoin, even if it is only 50 or 100 sats. Those sats are still part of the original 21 million coins.

That's to be expected.
But at least you're processing those requests manually, which is a good countermeasure.
But how about my concern that the cooldown automatically triggers without even using the "Claim" button?
Or do you mean that it's intended when you said that it's "the whole website", means that all links will trigger the cooldown regardless if the user claimed or not?
Yes, the manual process is slow, but for now it is also a useful safety layer. Maybe later I will figure out how to automate it slowly and safely, possibly through an independent server that is not directly connected to
https://thesatoshifaucet.com/ in any way, or maybe from my local machine.
Currently, I am testing with the LNBits open-source APIs.
About the cooldown, yes, it is across the website. I mean one claim per 10 minutes. However, if I get an IP from a unique country/location submitting a claim for the first time, then I may allow it without applying the 10-minute timer immediately.