A velocity check counts repeated events and reacts when a threshold trips. The interesting part is not the counting, it is choosing what counts as the same thing.
A BIN attack fixes one bank’s card range and varies everything else. Here is what that leaves behind in your own order data, and what it does not.
Eight labels, and most shops use three. Failed is a decline rather than an abandonment, and draft exists only because of the block checkout.
The decline reason your gateway gave is rarely on the order screen. It is in the notes panel beside it, written by machinery rather than by a person.
Failed orders are declines, not abandoned baskets. And the row count is not the attempt count, because WooCommerce reuses an order when the basket has not changed.
Bursts of small failed authorisations, repeated addresses and throwaway emails look nothing like ordinary declines. Here is how to tell them apart with evidence you already have.
A captcha on the checkout page only covers the request it is wired to. The block checkout places orders through the Store API, where classic checkout hooks never fire.