A Denial of Wallet attack keeps your LLM endpoint up and runs up the bill. Why request rate limits miss it, and the token-and-dollar controls that stop it.