
How MindMax Neutralized a Massive Bot Scraping Attack with CrowdSec WAF Bot Detection
Recently, we published an article digging into bot signal data received from the early alpha release of CrowdSec WAF’s bot detection feature. We highlighted the bot cluster we found and dubbed “paperphone”, a scraping network spanning 75,000 IPs across 43 countries (read the full story here). None of these insights would have been possible without our brave early adopters who tested the feature live in production. Today, we’re excited to share the story of one such adopter: MindMax.
The Challenge: A Stealthy, Highly Distributed Residential Botnet
MindMax is a small Finnish company running a handful of free consumer websites, including online dictionaries, a TV guide, a car marketplace, and a quiz platform. Run by a lean team of four, MindMax maintains a compact, self-hosted infrastructure dedicated to serving daily user needs seamlessly.
In early September 2026, MindMax’s online dictionary sites were hit by a massive scraping network. The attack was extraordinarily sneaky: it utilized hundreds of thousands of residential IPs, with each IP making only a single request. Coupled with legitimate browser headers and constantly rotating user agents, traditional rate limiting and IP reputation checks were completely useless; no single IP ever triggered standard alarm thresholds.
The persistent traffic spike threatened server performance and hurt MindMax’s ad-funded sites. CEO Juha and his team initially crafted custom Nginx rules, JavaScript cookie verification, and network fingerprint blocks. While these custom fixes provided temporary relief, the botnet rapidly adapted to every defense they threw at it.
The Solution: Open Source Bot Detection
Already relying on the CrowdSec Security Engine, MindMax eagerly jumped at the chance to test CrowdSec’s new bot detection feature in alpha. The solution perfectly aligned with their architectural values: open source, lightweight, running entirely on their own infrastructure, and requiring zero third-party traffic routing.
MindMax deployed the Security Engine alongside the CrowdSec WAF (AppSec component) and bot detection, using an OpenResty bouncer situated in front of PHP. They piloted the setup on one dictionary site before expanding protection across three portals, taking care to exempt verified search engine crawlers so SEO remained completely unharmed.
The Results: 99%+ Rejection Rate & Uninterrupted UX
The impact was immediate and dramatic:
- Massive Threat Neutralization: In the first week alone, roughly 1,000,000 challenges were served to suspicious clients.
- Over 99% Block Rate: More than 99% of non-human traffic failed or abandoned the challenge instantly.
- Zero Friction for Real Users: Genuine visitors passed challenges seamlessly in ~2 seconds, with search traffic remaining rock-solid.
- Accurate Targeting: Manual checks confirmed that only headless browsers and malicious crawlers were blocked; legitimate users experienced no interruption.
Looking Ahead
By stopping low-volume, highly distributed residential bots that traditional tools couldn’t touch, all while keeping full control of their self-hosted setup, MindMax successfully eliminated the bulk of their bot problem. CrowdSec continues to protect their infrastructure alongside custom rules, giving MindMax the peace of mind to focus on delivering great services to their users.


