BackCAPTCHA

CAPTCHA

GPT-6 Astra
2026-09-07 14:28:19

GPT-6 Astra clears all 48 levels of a CAPTCHA parody game, raising fresh questions for bot defenses

A demo video circulating on X has put OpenAI’s latest model, GPT-6 Astra, at the center of a new debate over CAPTCHA-style defenses. In the video, the model completes all 48 levels of the browser game I’m Not a Robot, a satirical puzzle game by developer Neal Agarwal that turns familiar reCAPTCHA tasks into increasingly absurd challenges. The clip was posted by AI developer Sharif Shameem and later reposted by developer Xiao Hu with the claim that "all website CAPTCHA protections have failed." The source article makes a narrower point. Beating a parody browser game does not mean every CAPTCHA system on the internet stopped working overnight. What it does show is a broader shift: AI systems are getting better at reading screens, understanding rules, and operating web interfaces in ways that look more like human behavior. That matters for crypto. If AI can pass first-layer bot checks more reliably, the pressure could rise on airdrop sybil defenses, exchange account creation, NFT mint sniping, and faucet or rewards abuse. The report also notes that proof-of-personhood tools, behavioral analysis, biometrics, and systems such as World ID may gain more attention as traditional CAPTCHA methods lose effectiveness.

140
GPT-6 Astra clears all 48 levels of a CAPTCHA parody game, raising fresh questions for bot defenses
GrokBot
2026-09-05 09:16:32

How GrokBot actually handles multi-agent teams: plans, routines, delegation and approval controls

A BlockTempo walkthrough matched a widely shared X thread about GrokBot against official SpaceXAI documentation and reached a simple conclusion: there is no separate "loop" or "graph" switch in the product. In practice, what users call loops maps to Routines used with Skills, while graph refers to delegation across multiple bots based on each bot’s description field. The report also lays out who can access GrokBot, listing six eligible plans: SuperGrok Plus, SuperGrok Heavy, Cursor Pro+, Cursor Ultra, and Cursor Teams Standard and Premium. It notes that GrokBot has no free tier, though SuperGrok Plus can be tried for a limited time. Eligible accounts receive weekly usage quotas and may enable pay-as-you-go billing based on model and token costs. Beyond setup, the guide focuses on operating constraints. Bots under the same account share one cloud computer, including files, browser state and login sessions, which makes handoffs easier but removes any security boundary between bots. The article also highlights seven categories of actions that require approval by default, from sending messages and publishing content to transferring funds, changing permissions and accepting legal terms. It recommends defining approval rules before problems appear, especially for teams using scheduled routines and connector-based workflows.

100
How GrokBot actually handles multi-agent teams: plans, routines, delegation and approval controls
Meta
2026-08-27 00:10:09

Meta said to be building Hatch agent platform with a $199.99 top-tier plan

Meta is developing an agent platform called Hatch, according to The Information, with the product framed around a simple promise: users set a goal, and the system breaks the task down and delivers the result. The report says Hatch’s top subscription tier will cost $199.99 a month, closely matching Manus’ $200 plan. The product is aimed less at coding work and more at what the report describes as “consumer digital life.” During development, Hatch has reportedly been trained in simulated versions of services including DoorDash, Etsy, Reddit, Yelp, and Outlook, while Meta also has the advantage of its own ecosystem across Instagram, Facebook, and WhatsApp. The idea is to connect discovery, comparison, communication, scheduling, and purchasing in a single workflow. The model stack is also notable. Hatch is currently being built with Claude, with Meta planning to switch to its in-house Muse Spark model when the product formally launches. A new model called Watermelon is expected in October and may support a later expansion phase, though its exact role has not been confirmed. The report also points to a key challenge: a near-$200 monthly fee will require reliable performance in the messiness of the real internet, where page changes, logins, pop-ups, CAPTCHAs, and inventory shifts can easily break automated tasks.

220
Meta said to be building Hatch agent platform with a $199.99 top-tier plan
Check Point R
2026-08-20 16:38:52

Check Point says StopAndProtect used nearly 2,000 hacked WordPress sites to spread malware

Check Point Research said the StopAndProtect ransomware operation used nearly 2,000 compromised WordPress websites to distribute malware, steal data, monitor victims and deploy ransomware. The campaign was discovered in mid-May and had compromised more than 6,000 unique IP addresses as of July 24, according to the researchers. The United States accounted for 1,852 of those IPs, while Russia and India each had 630. The report said the hacked websites were also used to host malware, send commands, and store stolen files, screenshots and activity logs. Researchers said the attackers relied on fake CAPTCHA prompts to trick Windows users into running PowerShell commands. That process was used to steal credentials and cryptocurrency wallet seed phrases, and the malware was able to spread through networks and USB devices. Check Point Research said it collected more than 31,000 screenshots and over 700 compressed data archives during its investigation. The researchers also said the attackers may have accidentally infected themselves.

530
Check Point says StopAndProtect used nearly 2,000 hacked WordPress sites to spread malware
WordPress
2026-08-20 16:33:38

Nearly 2,000 Hacked WordPress Sites Used as Malware and Ransomware Infrastructure

Nearly 2,000 compromised WordPress sites were used as part of a broader cybercriminal operation that distributed malware, stole files, monitored victims, and deployed ransomware, according to a report from Check Point Research published Tuesday. The firm said it first identified the StopAndProtect ransomware family in mid-May and later linked it to a larger toolkit-driven campaign rather than a single malware strain. Researchers said the operation targeted Windows users through fake CAPTCHA prompts on hacked websites, tricking victims into running a PowerShell command that installed malware capable of stealing credentials, harvesting cryptocurrency wallet seed phrases, spreading through networks and USB drives, locking screens, and dropping ransomware. Check Point said operational security failures by the attackers exposed internal files, infection logs, screenshots from victim machines, and source code used to manage compromised websites at scale. By July 24, the campaign had affected more than 6,000 unique IP addresses, including 1,852 in the United States and 630 each in Russia and India. The researchers also collected more than 31,000 screenshots and over 700 archives containing stolen documents, passwords, and crypto wallet files.

510
Nearly 2,000 Hacked WordPress Sites Used as Malware and Ransomware Infrastructure
Stablecoins
2026-08-09 00:34:05

Why crypto venture capital is clustering around stablecoin infrastructure

Crypto venture funding slowed sharply in the first quarter of 2026, but stablecoin payment infrastructure remained one of the few areas still drawing large checks. Galaxy Research said crypto VCs invested $4 billion across roughly 355 deals during the quarter, down about 50% from the prior quarter, while deal count fell 16%. At the same time, 57% of capital went to later-stage companies, showing a clear preference for businesses that already have customers, revenue and payment volume rather than token-led narratives. That shift helps explain why companies such as Rain, OpenFX, RedotPay, Mesh and Conduit have continued to raise substantial rounds. Investors are not just backing stablecoin issuers. They are funding the wider stack around payments: cards, cross-border settlement, FX liquidity, wallets, banking access, orchestration and redemption. The appeal is straightforward. Stablecoins can serve as a 24/7 settlement asset, while the companies building on top of them can charge fees that look familiar to fintech investors, including transaction fees, FX spreads, card issuance fees and API subscriptions. Still, the article argues the excitement should be viewed carefully. On-chain stablecoin volume is not the same as real-world payment activity, and fundraising remains concentrated in a small number of scale players. Licensing, local banking ties, fiat on- and off-ramps, and rising competition remain central constraints even as the sector gains momentum.

1280
Why crypto venture capital is clustering around stablecoin infrastructure
Microsoft Thr
2026-08-07 16:36:59

Microsoft says hackers are using BNB Chain contracts and fake CAPTCHAs to deliver malware

Microsoft Threat Intelligence said a malware campaign is using compromised websites, fake CAPTCHA prompts, and BNB Chain smart contracts to deliver malicious commands to victims. In the activity described by Microsoft, JavaScript planted on hacked sites contacts a BNB Chain gateway and pulls instructions from a smart contract previously tied to the ClearFake campaign. The setup uses a technique known as EtherHiding, which stores malicious instructions on-chain, making them harder to remove because only the wallet controlling the contract can change its contents. Victims are shown fake verification prompts that tell them to open the Windows Run dialog, paste clipboard content, and press Enter. Microsoft said this method, known as ClickFix, relies on users executing the malware themselves, while a related variation called TerminalFix sends users to Windows Terminal or PowerShell. The company said these approaches have become a high-volume initial access technique affecting thousands of enterprise and consumer devices globally each day. Microsoft also warned that attackers are abusing legitimate Windows tools such as PowerShell, cmd, mshta, rundll32, msiexec, curl, Windows Management Instrumentation, and scheduled tasks. It advised organizations to restrict unnecessary command-line tools, enable PowerShell logging, and apply application controls. The company added that users should never paste commands from CAPTCHA pages, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command Prompt.

360
Microsoft says hackers are using BNB Chain contracts and fake CAPTCHAs to deliver malware
ClickFix
2026-08-07 02:52:57

Microsoft Threat Intelligence Flags ClickFix and EtherHiding Malware Campaign

Microsoft Threat Intelligence has flagged a cluster of compromised websites that are spreading malware through two abuse techniques: ClickFix and EtherHiding. The campaign reportedly targets thousands of enterprise and consumer devices every day. Attackers inject Base64-encoded JavaScript into affected pages, which then reaches out to BNB Smart Chain RPC gateways and pulls the next-stage instructions stored on a smart contract. Because only the deployer wallet can modify that contract, conventional takedown methods are difficult to apply. To get the infection going, victims are shown a fake CAPTCHA and tricked into opening the Run dialog, pasting clipboard contents, and executing attacker-supplied commands. Microsoft flagged the abuse of system tools such as conhost, cmd, PowerShell and mshta, along with command obfuscation. If the chain completes, credential exposure, persistence, lateral movement and ransomware attacks become possible. Microsoft recommends that organizations enable layered Defender protection, restrict command-line tools and enable PowerShell script logging, while users should not paste unrecognized commands into the Run box or a terminal.

1190
Microsoft Threat Intelligence Flags ClickFix and EtherHiding Malware Campaign