Researchers pull a login token out of Cloudflare's edge with a browser-era ghost bug
A Spectre-style side-channel attack ran inside one Cloudflare Worker and quietly read data from another sitting on the same machine, at speeds fast enough to lift a JSON Web Token in seconds.

Key points
- Academic researchers demonstrated a remote Spectre attack against Cloudflare Workers running in production, not a lab clone.
- The attack leaked a JSON Web Token, the digital pass that proves who a user is, from a second Worker sharing the same server.
- Data flowed out at up to 12 bits per second, about 360 times faster than a similar 2021 proof of concept.
- Both the attacker code and the victim code were controlled by the research team, so no real customer data was exposed.
- The finding revives long-standing questions about running many customers' code on shared processors.
A team of academic researchers has shown that a hardware flaw first made famous in 2018 is still very much alive at the cloud edge. Their target: Cloudflare Workers, the service that lets developers run small pieces of code inside Cloudflare's global network, close to end users.
The attack, first reported by The Hacker News, used one Worker to secretly read the memory of another running on the same physical server. The prize was a JSON Web Token (JWT), the small signed string a website hands your browser after you log in to prove you're still you. Steal one and you can often impersonate the user until it expires.
What did the researchers actually do?
They built two Workers. One acted as attacker, the other as victim, holding a JWT in memory. Both deployed to Cloudflare's production environment, the same infrastructure paying customers use, and the researchers waited for the platform to schedule them onto the same machine.
Once co-located, the attacker Worker ran a Spectre-style side-channel attack, tricking the processor into work it shouldn't do, then measured tiny timing differences to reconstruct the secret left behind. Leak rate: up to 12 bits per second, roughly 360 times the speed of a comparable 2021 experiment. A short JWT falls in seconds, not hours.
We covered the Spectre family again on 6 August, when MIT CSAIL found a way to slip past Spectre v2 kernel defences by re-poisoning the branch predictor in the window after the CPU cleans it. The pattern here is familiar: researchers keep finding the ceiling on these mitigations.
Should Cloudflare customers be worried right now?
No confirmed real-world abuse. The victim Worker was researcher-controlled, so no customer JWTs were taken. The architectural problem's harder to dismiss, though. Workers, like many serverless platforms, pack thousands of tenants onto shared hardware, and Spectre-class flaws live in that hardware.
Cloudflare has previously argued that its V8 isolate model, the lightweight sandbox each Worker runs inside, plus timing defences, made Spectre impractical at their scale. This research pokes directly at that claim. You can isolate processes in software all you like. If two workloads share a CPU core and its caches, a patient attacker can sometimes read across the fence. That's been true since 2018 and it's still true now.
What ordinary users should do
Nothing dramatic. No sites are known to have been breached. If you're worried about session tokens, the same habits help: log out of sensitive accounts when you're done, turn on multi-factor authentication, and treat surprise "you've been logged out" prompts as a signal worth checking.
The numbers at a glance
| Detail | Value |
|---|---|
| Platform targeted | Cloudflare Workers (production) |
| Data leaked in test | A JSON Web Token from a co-located Worker |
| Leak rate | Up to 12 bits per second |
| Speed vs 2021 attack | About 360 times faster |
| Real customers affected | None reported; both Workers were researcher-controlled |
Shared silicon keeps writing cheques the sandbox has to cash. Serverless is cheap because it's crowded, and crowded is exactly what Spectre likes. If your app puts long-lived bearer tokens in memory on a shared runtime, shorten their lifetime and bind them to a client fingerprint. The neighbour may be measuring.



