A WordPress nonce is not used once. It is valid for a window, and a cached checkout page carries one minted for somebody else. Your own test order passes because you are signed in.
The Store API carries its own limiter, switched off out of the box. Turning it on takes one filter, and getting it right takes an accurate client address.
The form is on the checkout page. The request that places the order is not, and anything wired to the page template never sees it.
The Checkout block posts JSON to a REST route. Code hooked to the classic checkout is never asked, which is why protection can look healthy and do nothing.
WooCommerce ships a second payment surface for orders that already exist. It calls your gateway directly, and none of your checkout validation runs there.
WooCommerce treats one page as the checkout. Any other page carrying the form can still place orders, and a captcha wired to the assigned page never sees them.