Possibly AI company crawlers. When they came up there was a lot of bad publicity and reports of actively malicious and toxic crawling behavior, including ban evasion.
You can think about locking some url paths behind valid login sessions, or use a proof of work proxy guard.
Anubis is the popular tool for that. I've seen maybe three alternatives, one of which from Cloudflare.
See also related Codeberg ticket (Forgejo instance) https://codeberg.org/forgejo/discussions/issues/319
If you search, you can find various blog posts about these issues. Not just when Forgejo.