The game is intended for publishing on iOS and Android.
Android users can get API URLs from ADB logs. After that, they can get an authentication token and use curl to send requests very fast to outmatch opponents.
I doubt I can force them to use captcha every minute, because well, the game is designed to be clicked as fast as you can.
How can I protect my game backend from this attack vector?