Security · 2h ago
Researcher Finds Cloudflare Turnstile Bypass, Gets Denied Bug Bounty
A security researcher discovered that Cloudflare Turnstile's CAPTCHA token can be copied from one browser and reused in another, bypassing the challenge entirely. The researcher reported the flaw with proof, but Cloudflare deemed it out of scope under a policy excluding automated bypasses, despite the manual method. Cloudflare is fixing the issue without compensating the researcher.
Meridian48 take
The incident highlights a common bug bounty grievance: vague scope policies that let companies benefit from researcher work without paying out.
Read the full reporting
How I Found a Critical Cloudflare Turnstile Bypass – And Got Denied a Bounty →
DEV Community
cloudflare-turnstilebug-bounty