These suggestions sound good but the real challenge will be to reliably detect fake logins to not suddently and accidentally mess with your real users..
OP mentioned the attack is easily identified so legitimate traffic gets served correctly bad traffic gets "logged in" to the poisoned honeypot. 301 after login perhaps