In the current form, the 'customer_shopping_points_spending' variable from checkout_payment.php could be fed with a higher number than available on ones account and be deducted to the total amount in the checkout_confirmation page.

More...