Cloudflare Workers Exploit Achieves 360x Faster JWT Theft via Spectre Attack

Cloudflare Workers Exploit Achieves 360x Faster JWT Theft via Spectre Attack

First seen 20 Aug 2026, 22:53 UTC ThehackernewsTechtimesblog.cloudflare.com 82% similarity 51.9

Article Content

Browse articles
ThreatCluster

Researchers demonstrated a Spectre-class side-channel attack that can steal JSON Web Tokens (JWTs) from Cloudflare's serverless infrastructure at a rate of 12 bits per second, 360 times faster than previous methods. This attack exploits a feature intended for legitimate tasks, allowing it to evade detection. Conducted by engineers from Cloudflare, Graz University of Technology, and the University of Edinburgh, the research shows that Spectre attacks are evolving and not merely theoretical. Cloudflare confirmed that no evidence of this technique being used maliciously was found, despite the attack's successful execution in a live environment. The findings were published on August 19, 2026, alongside an academic paper detailing the methodology. The attack leverages speculative execution flaws in modern CPUs, which have been known since the Spectre vulnerability disclosure in January 2018. Mitigations were already in place, but the new attack method demonstrates significant improvements in speed and reliability.

Key Points: • Spectre attack can steal JWTs from Cloudflare at 12 bits per second. • The attack is 360 times faster than previous methods and evades detection. • No evidence of the exploit being used maliciously was found in Cloudflare's environment.

ThreatCluster AI How this analysis works

Timeline

2018-01-01
Spectre vulnerability disclosed
The Spectre vulnerability was publicly disclosed, affecting modern CPUs through speculative execution flaws.
Techtimes
2021-01-01
First proof-of-concept Spectre attack published
Cloudflare and TU Graz researchers published a proof-of-concept attack demonstrating JWT leakage at 120 bits per hour.
Techtimes
2026-08-19
New Spectre attack findings published
Cloudflare published research showing a new Spectre attack that leaks JWTs at 12 bits per second, significantly faster than previous methods.
Techtimes
2026-08-20
Current status of the attack
Cloudflare confirmed no evidence of the new attack being exploited in the wild despite its successful demonstration.
Techtimes

Community

Browse all →

Tracked Entities in This Story