You get a cease and desist letter, you cease and desist doing the stuff if you don't want / can't afford a legal fight.
Then you post the cease and desist letter on your website, and post about it on hacker news.
Then you post the cease and desist letter on your website, and post about it on hacker news.
Very risky business.
The likelihood of things breaking or behaving in unexpected ways are data points I think about when assessing risk irrespective of whether an API is public or not. In some industries even the public APIs are more risky than using the unofficial Venmo API likely is.