Researchers Demonstrate Data-Leaking Attack on Cloudflare Workers
Cybersecurity researchers have revealed a remote 'Spectre' attack targeting Cloudflare Workers, a popular platform businesses use to run code close to their customers for faster website and app performance. The attack allowed a malicious Worker to slowly leak a JSON Web Token (JWT) — a type of digital credential often used to verify user identity — from another Worker running on the same physical server, achieving a leak rate of up to 12 bits per second. That may sound slow, but it's 360 times faster than a similar attack demonstrated back in 2021, showing that these side-channel techniques are becoming more practical over time.
The researchers conducted their test in a controlled, end-to-end experiment using both an attacker-controlled Worker and a victim Worker, successfully proving the technique works in a real production-like environment rather than just theoretically. Spectre-style attacks exploit flaws in how modern computer processors handle speculative execution, a performance-boosting technique, rather than relying on traditional software bugs — making them notoriously difficult to fully patch.
While this particular research focused on Cloudflare's infrastructure, it highlights a broader concern for any business relying on shared cloud or edge computing environments: sensitive data can potentially be exposed through subtle hardware-level side channels, even when applications are properly coded. Businesses should stay informed about vendor security advisories and ensure sensitive credentials have short lifespans to limit exposure.