Fetching from the wire…
Public story · 2026-07-22 · high
Only reCaptcha v3 slowed agents down, and just until researchers matched the execution environment.
Why now: The bypass paper is part of the July 22 briefing on bot defenses.
A paper posted to arXiv ran six LLM browser-agent setups and seven commercial solver services against hCaptcha, reCaptcha v2, reCaptcha v3, and Cloudflare Turnstile. The result: near-perfect bypass, at negligible cost, across almost every configuration.
That's the headline stat, but the isolation is the real finding. Non-interactive reCaptcha v3, which scores behavior instead of asking you to click anything, held up better than the rest. Then it fell too, once the researchers matched the execution environment the agent was running in. Behavior didn't matter. Environment did.
If you've shipped a signup form, a checkout flow, or an API rate limiter behind CAPTCHA, this is your threat model changing under you. The whole category, click-the-traffic-lights, invisible scoring, Turnstile's silent checks, assumes a bot looks or acts differently from a human. This paper says that assumption is dead. An agent running in an authentic browser environment doesn't act differently. It just acts.
I've leaned on Turnstile and reCaptcha v3 in projects because they're cheap and mostly invisible to real users. This is the kind of result that makes me want to check what's actually gating my forms versus what I've just assumed is gating them.
The paper doesn't say what a working defense looks like. It doesn't test server-side attestation, hardware-backed environment proofs, or anything that verifies the browser instance itself rather than what it does inside the page. That's the gap. If you're building anti-bot into a product, the falsifiable claim here is concrete: any defense that scores behavior instead of verifying the runtime is already beaten, you just haven't measured it yet.
Each link below shares sources, entities, or timing with this story.
Simon Willison released LLM / Shared entity: LLM / Shared topic / Earlier coverage
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; overlapping topics (against, detection).
Simon Willison released LLM / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-18.
LLM uses OpenAI / Shared entity: LLM / Earlier coverage
Linked by a graph relationship (LLM uses OpenAI); both cover LLM; earlier LLM coverage from 2026-06-19.
Simon Willison released LLM / Shared entity: LLM / Earlier coverage
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-07-14.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-22.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-10.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-10.