That's a design bug, not a user problem.
Why are zero-length passwords treated as login attempts for a user with a non-zero password? Why are a cluster of login attempts permitted in such quick succession? There's so many obvious fixes here for what is apparently a common issue.