{"slug": "are-captchas-still-bot-hard", "title": "Are CAPTCHAs Still Bot-Hard?", "summary": "Researchers report the first general CAPTCHA-solving solution, Halligan, built on a state-of-the-art vision language model (VLM) that solves unseen visual CAPTCHAs without any adaptation, challenging the AI-hard assumption behind reCAPTCHA v2, hCaptcha, and GeeTest. Halligan works by reducing any CAPTCHA to a search problem, transforming the CAPTCHA question into an optimization objective and the CAPTCHA body into a search space, using well-designed prompts on known VLMs to generalize to almost any existing CAPTCHA.", "body_md": "Visual CAPTCHAs, such as reCAPTCHA v2, hCaptcha, and\n        GeeTest, are mainstream security mechanisms to deter bots\n        online, based on the assumption that their puzzles are AI-hard but human-friendly. While many deep-learning based\n        solvers have been designed and trained to solve a specific\n        type of visual CAPTCHA, vendors can easily switch to out-of-distribution CAPTCHA variants of the same type or even\n        new types of CAPTCHA, with very low cost. However, the\n        emergence of general AI models (e.g., ChatGPT)\n        challenges the AI-hard assumption of existing CAPTCHA\n        practice, potentially compromising the reliability of visual\n        CAPTCHAs.\n\n \nIn this work, we report the first general CAPTCHA solving\n        solution, Halligan, built upon the state-of-the-art vision language model (VLM), which can effectively solve unseen visual CAPTCHAs without making any adaption. Our rationale\n        lies in that almost any CAPTCHA can be reduced to a search\n        problem where (i) the CAPTCHA question is transformed\n        into an optimization objective and (ii) the CAPTCHA body is\n        transformed into a search space for the objective. With well\n        designed prompts built upon known VLMs, the transformation can be generalized to almost any existing CAPTCHA.", "url": "https://wpnews.pro/news/are-captchas-still-bot-hard", "canonical_source": "https://halligan.pages.dev/", "published_at": "2026-10-07 07:48:54+00:00", "updated_at": "2026-10-07 08:19:11.564293+00:00", "lang": "en", "topics": ["artificial-intelligence", "computer-vision", "large-language-models", "ai-safety"], "entities": ["Halligan", "reCAPTCHA v2", "hCaptcha", "GeeTest", "ChatGPT"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/are-captchas-still-bot-hard", "markdown": "https://wpnews.pro/news/are-captchas-still-bot-hard.md", "text": "https://wpnews.pro/news/are-captchas-still-bot-hard.txt", "jsonld": "https://wpnews.pro/news/are-captchas-still-bot-hard.jsonld"}}