For anyone dealing with this have you established if the bots are :
- actually interacting with the page, triggering analytics events etc
- loading the frontend, but using the ajax api to actually interact with the cart
- or possibly newer abusing the new system for the MCP storefront api which also has cart functionality etc ( lets LLMs like chatgpt access store data on the frontend)
- Mimics common browser user agents and request headers, appearing identical to real users> - Reaches storefront pages, skewing sessions, bounce rates, conversion rates, and marketing attribution> - Then exploits Shopify’s architecture to bypass front-end logic and spam cart activity at scale