It seems you are letting any client with a session token update the entire wall. The endpoint simply takes the base64 PNG and sets it as the wall.
I was thinking maybe taking a diff, limiting its maximum area, and rate-limiting might at least discourage that.