Hmmm.

You could go the pain in the ass track down and hassle people mode, which may or may not work, or you could setup some type of mechanism to black-hole their IP address after 'X' number of failures. Preferably on a device BEFORE your web server gets hit.