They use services like this. Almost all of them do - I used to build bot defence for streetwear related stuff. Like I said, it is an arms race. It's just like anticheat in online games, where the defending side needs to run invasive dynamically sent code as admin at all times and collect unnecessarily insane amounts of PII and data .
Almost all major merchants use something similar, usually some kind of free product like Akamai's "included" product botmanager if they happen to use Akamai, or Cloudflare Bot Management, etc. Go on staples.com/target.com/tjmaxx.com/..any major brand for instance and look at the far bottom of the page, you'll see a blob of randomly generated filenames being included as JS - ctrl+f "/akam/". The setBm call here is botmanager.
The buyer side is doing CFAA-illegal mass-scale BGP hijacking, wire fraud, carding, forgery of legal documents and letters of authorisation, and using hacked mobile devices, malware, botnets to get proxies to burn, on occasion DDoSing sites to try and "stop anyone else from getting them if I can't" type of behaviour.
The seller side is sending invasive obfuscated, packed, borderline-abusive code (JS, wasm, webgl, enumerating fonts, running WebRTC, running Flash, running Java, sending .m3u playlists to try and get a media player addon to load, etc...) to execute on every client to try and detect automation and associate accounts together with persistent aggressive tracking. I see payloads where they try to extract a LAN IP via WebRTC and then try to port scan the entire /24 and localhost via <img onerror> and websockets, or bruteforce several 192.168/24 netblocks.
I don't know about nvidia. I haven't known nvidia to ever sell stuff directly, though. Not sure about the 3xxx launch - I would assume they do this so rarely it hasn't come up often.