Malicious dupes generally exploit the physics engine (Havok) or entity limitations within the Source SDK. The most common methods include:

The most effective defense remains a dedicated team of administrators using updated anti-cheat tools.

I can provide tailored configuration steps to lock down your server. Share public link