1) cloudflare 2) captcha 3) requiring unique phone number upon account sign up
I'm considering requiring unique phone numbers but am concerned that will stop too many legitimate users from signing up.
You can also require an email address as well if you prefer.
It's definitely going overboard, but I've personally never experienced bots really signing up for anything I've made.
Sounds like you have a great product that bots can take advantage of if you have that many signing up.