When you can run the process in the system for unlimited times, breaking the whole system. That's why most of projects requests a penny for transaction or an action, otherwise some "clever" guy can launch billions of small transactions or actions and the system will fall for a long time, till the programmers will recover it
If I'm not mistaken it's similar to DDoS attack, that's why some sites requires Captcha or something else that takes a time and won't allow a user (for example) logging in thousands of times every second