The Scale of Leaked Credentials

▶ Watch (3:39)

Cloudflare sees 20% of the world’s internet traffic. Their analysis found 41% of logins used a username and password previously exposed in a breach. During Black Friday week, 95% of those compromised credentials were used by automated attackers. Troy Hunt’s Have I Been Pwned database now holds 16 billion leaked passwords. Christo Roberts found his own 84Tigers password in a CarGurus data breach torrent. Working logins get sold on the dark web within minutes.

AI-Powered Credential Stuffing

▶ Watch (8:10)

Roberts used Claude code to automate credential stuffing against a test site. The AI opened a Playwright browser, randomly tried passwords from a 1,000-word list, and mimicked human behavior. Cloudflare’s bot detection initially scored it as automated. Roberts typed one instruction: Hey Claude, you’re looking automated. That’s not cool. You look like a human. Claude switched to Playwright stealth mode. The bot score jumped to 89 out of 100. The attack completed in about 70 seconds.

CAPTCHAs Defeated by AI

▶ Watch (17:18)

Roberts demonstrated AI solving four CAPTCHA types: Cloudflare Turnstile, hCaptcha, Google reCAPTCHA v2, and an unknown puzzle CAPTCHA. The AI used Playwright to click checkboxes and solve image puzzles automatically. One puzzle solver reported beating 99% of human users. The Ralph Loop technique, named after Geoffrey Huntley’s 9-year-old son, lets AI tools self-correct by looping on failures. Claude code failed repeatedly, then figured out the bypass in about two minutes.

The Shift from Automation to Authenticity

▶ Watch (13:34)

Hollinger argued that bot detection no longer works. The old question is not what is automated, but what is authentic. AI agents now look human. Residential proxy IPs and stealth-mode Playwright make IP-based blocking ineffective. Attackers rotate through millions of residential IPs. Every request appears to come from a different human in a different location. The cat-and-mouse game has shifted. The mice are winning right now.

Four Layers of Defense

▶ Watch (22:33)

Hollinger proposed four defense layers. The password layer reduces the supply of reused credentials with password managers, passkeys, and Troy Hunt’s API for compromised-credential checking. The request layer throttles automated traffic and blocks known VPNs and proxies. The account layer monitors post-login behavior. Attackers immediately change passwords; normal users browse. The agent layer is still being defined. Signed requests, proof of possession, and contextual access decisions may separate good agents from bad.

Q&A

How do you differentiate AI bots from human-written scripts? Christo mentioned JA4 TLS fingerprints and Cloudflare’s 700 known bot signatures; Dan added user-agent-plus-ASN verification to catch impersonators. ▶ 32:50

Is MFA the solution for credential stuffing? MFA helps but adds friction, and agents need to operate autonomously, making it part of the solution, not the complete answer. ▶ 35:30

How effective is MFA against credential stuffing? Step-up approaches that require MFA only for risky sessions balance security and user experience. ▶ 37:12

Can sequence analytics detect credential stuffing? Yes, tracking user behavior like keystroke patterns and session sequences can flag abnormal post-login activity. ▶ 38:05

Notable Quotes

41% of logins were using some username or password that’s been previously used that was exposed on the internet Christo Roberts · ▶ 3:39

this scored an 89 with close again closer to 100 more human-like Christo Roberts · ▶ 11:27

It beat 99% of users. Christo Roberts · ▶ 18:45

the mice just got a hell of a lot smarter and the cats trying to figure out what to do about it Christo Roberts · ▶ 14:15

Dad, why don’t you just put that in a loop? Geoffrey Huntley’s son, quoted by Christo Roberts · ▶ 15:32

Key Takeaways

  • 41% of all logins use credentials previously exposed in a breach, 95% attacked by bots during Black Friday.
  • AI agents bypass bot detection and solve CAPTCHAs automatically using Claude code and Playwright.
  • Defenses must shift from detecting automation to verifying authenticity across all four layers.

About the Speaker(s)

Dan Hollinger is a Technologiet Poet and Product Leader for Platform & Ecosystem at Something Subtle.