"We design and develop a low-cost, end-to-end system to break hCaptcha service.
• We evaluate our system against 270 live hCaptcha challenges and achieve the success rate of attack over 95% with the system taking less than 19 seconds to crack a challenge on average.
• We provide a preliminary security analysis of the hCaptcha system. Our analysis shows that the hCaptcha service employs minimal to no mechanism to resist automated abuses other than asking users to solve a simple image recognition task."
The most amusing part, though, is the gaslighting by the hCAPTCHA team and the denial they live in lol
"We reported our attack and countermeasures to the hCaptcha security team to help them make the system more robust to automated attacks. They responded that their system would have been pretty confident that our traffic was automated based on the techniques we used, and we would never have observed additional countermeasures. However, we did not notice any measures preventing our bot from passing the image CAPTCHA tests during our experiment.
"
The most amusing part, though, is the gaslighting by the hCAPTCHA team and the denial they live in lol
"We reported our attack and countermeasures to the hCaptcha security team to help them make the system more robust to automated attacks. They responded that their system would have been pretty confident that our traffic was automated based on the techniques we used, and we would never have observed additional countermeasures. However, we did not notice any measures preventing our bot from passing the image CAPTCHA tests during our experiment. "