>I'd be looking pre-emptively block OpenAI endpoints

From what I've seen the requests in these attacks rarely come from known OpenAI IPs and instead from Digital Ocean/AWS and TOR exit nodes.

As they say, agents are better at masking their end points than most hackers.