← Back to brief
ResearchOfficialPreprintarXiv Cryptography and Security

Broken Gates: Re-evaluating Web Bot Defenses in the Age of LLM Agents

A systematic measurement study assesses the effectiveness of current web bot defenses against LLM-based browser agents and commercial captcha-solving services. The study finds that challenge-based defenses like hCaptcha and reCaptcha v2 are broadly ineffective, as they can be bypassed by both commercial solvers and LLM agents with solver modules. Non-interactive defenses such as reCaptcha v3 show stronger resistance, but this is due to checks on execution-environment authenticity rather than agent behavior. The results indicate that the true security boundary for these defenses is at the environment layer.

Why it matters: This work highlights a fundamental shift in web security, showing that as LLM agents become more capable, traditional bot defenses are increasingly ineffective and future protections must focus on environment authenticity.

Full story at: arXiv Cryptography and Security

More coverage