The defence only acted when a request finished — so the researchers never finished the request
2026-08-20Security
Cloudflare and University of Edinburgh researchers pulled a JWT out of a co-located Worker at 12 bits a second with 99% accuracy, in production. No V8 exploit, no sandbox escape. The detection system was bypassed by holding one invocation open for hours, and the fix in the end was hardware.