I'm not from OSM but could you say more about malicious uses of captchas or how it's related to phishing?
Victims just click through the captcha without thinking, but it makes automatic verdicting by security scanners a pain because they just see a captcha page: can't tell the brand being impersonated, or even if it's a phishing site
I wrote a post about a number of these which actually pretend to be Cloudflare! https://phish.report/blog/fake-cloudflare-interstitials
But yeah, I wouldn't even know where to report those API keys for abuse