Solving Anubis's SHA-256 Proof-of-Work Challenge A developer documented how to solve the SHA-256 proof-of-work challenge used by Anubis, the open-source reverse-proxy anti-bot gate deployed by sites including Startpage, entirely server-side without a headless browser. The writeup derives the algorithm from Anubis's public source, showing that at difficulty 6 the winning nonce typically lands under 1000 and the search completes in low single-digit milliseconds, and notes the deployment-specific verification cookie must be captured and replayed on the pass-challenge request. Anubis TecharoHQ/anubis is an open-source reverse-proxy anti-bot gate an increasing number of sites put in front of themselves Startpage among them . When it decides to challenge a client, it serves a page embedding a PoW puzzle that the browser's JS solves in a Web Worker, then replays the answer as a query string against a fixed API path. Replicating that server-side unlocks the real page instead of the "Just a moment..." wait screen — no headless browser needed. Everything below is derived directly from Anubis's own public source lib/challenge/proofofwork/proofofwork.go for the server-side validator, web/js/worker/sha256.ts and wasm/pow/sha256/src/lib.rs for the two reference client implementations, which agree exactly — not reverse-engineered from obfuscated code. HTTP 200 Content-Type: text/html < doctype html