Cloudflare R2 DoW attack
Cloudflare doesn't charge for egress, but if somebody decides to send 1 trillion requests to the root of my R2 custom domain, which would trigger Class B operations, am I going to be charged for that? If so, then it's a clear-cut way to cause a denial-of-wallet attack.