I was thinking about it extensively this morning and the only solution I came up with was to accept only "new" events eg. X seconds from created_at but this has a lot of downsides too.
Requiring auth and enforcing protected events sounds good but yeah there's the client issue.