The Scale of Leaked Credentials
Cloudflare sees 20% of the world’s internet traffic. Their analysis found 41% of logins used a username and password previously exposed in a breach. During Black Friday week, 95% of those compromised credentials were used by automated attackers. Troy Hunt’s Have I Been Pwned database now holds 16 billion leaked passwords. Christo Roberts found his own 84Tigers password in a CarGurus data breach torrent. Working logins get sold on the dark web within minutes.
AI-Powered Credential Stuffing
Roberts used Claude code to automate credential stuffing against a test site. The AI opened a Playwright browser, randomly tried passwords from a 1,000-word list, and mimicked human behavior. Cloudflare’s bot detection initially scored it as automated. Roberts typed one instruction: Hey Claude, you’re looking automated. That’s not cool. You look like a human. Claude switched to Playwright stealth mode. The bot score jumped to 89 out of 100. The attack completed in about 70 seconds.
CAPTCHAs Defeated by AI
Roberts demonstrated AI solving four CAPTCHA types: Cloudflare Turnstile, hCaptcha, Google reCAPTCHA v2, and an unknown puzzle CAPTCHA. The AI used Playwright to click checkboxes and solve image puzzles automatically. One puzzle solver reported beating 99% of human users. The Ralph Loop technique, named after Geoffrey Huntley’s 9-year-old son, lets AI tools self-correct by looping on failures. Claude code failed repeatedly, then figured out the bypass in about two minutes.
The Shift from Automation to Authenticity
Hollinger argued that bot detection no longer works. The old question is not what is automated, but what is authentic. AI agents now look human. Residential proxy IPs and stealth-mode Playwright make IP-based blocking ineffective. Attackers rotate through millions of residential IPs. Every request appears to come from a different human in a different location. The cat-and-mouse game has shifted. The mice are winning right now.
Four Layers of Defense
Hollinger proposed four defense layers. The password layer reduces the supply of reused credentials with password managers, passkeys, and Troy Hunt’s API for compromised-credential checking. The request layer throttles automated traffic and blocks known VPNs and proxies. The account layer monitors post-login behavior. Attackers immediately change passwords; normal users browse. The agent layer is still being defined. Signed requests, proof of possession, and contextual access decisions may separate good agents from bad.
Q&A
How do you differentiate AI bots from human-written scripts? Christo mentioned JA4 TLS fingerprints and Cloudflare’s 700 known bot signatures; Dan added user-agent-plus-ASN verification to catch impersonators. ▶ 32:50
Is MFA the solution for credential stuffing? MFA helps but adds friction, and agents need to operate autonomously, making it part of the solution, not the complete answer. ▶ 35:30
How effective is MFA against credential stuffing? Step-up approaches that require MFA only for risky sessions balance security and user experience. ▶ 37:12
Can sequence analytics detect credential stuffing? Yes, tracking user behavior like keystroke patterns and session sequences can flag abnormal post-login activity. ▶ 38:05
Notable Quotes
41% of logins were using some username or password that’s been previously used that was exposed on the internet Christo Roberts · ▶ 3:39
this scored an 89 with close again closer to 100 more human-like Christo Roberts · ▶ 11:27
It beat 99% of users. Christo Roberts · ▶ 18:45
the mice just got a hell of a lot smarter and the cats trying to figure out what to do about it Christo Roberts · ▶ 14:15
Dad, why don’t you just put that in a loop? Geoffrey Huntley’s son, quoted by Christo Roberts · ▶ 15:32
Key Takeaways
- 41% of all logins use credentials previously exposed in a breach, 95% attacked by bots during Black Friday.
- AI agents bypass bot detection and solve CAPTCHAs automatically using Claude code and Playwright.
- Defenses must shift from detecting automation to verifying authenticity across all four layers.
About the Speaker(s)
Dan Hollinger is a Technologiet Poet and Product Leader for Platform & Ecosystem at Something Subtle.