TLDRocket
Sign in

A developer built a CAPTCHA that took Claude 5 10 minutes and 100K tokens to solve

Reddit

A dev built a CAPTCHA that took Claude 5 ten minutes and 100,000 tokens to crack. Turns out making AI burn time and money beats making puzzles humans can't solve either.

Based on reporting by Reddit — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

CAPTCHAs have always been a numbers game, and for a while the AI side was winning. Vision models got good enough to blast through squiggly text and picture grids in seconds, which left the whole system looking obsolete. One developer decided to flip the math instead of trying to out-design the bots.

The trick isn't cleverness, it's cost. Instead of building a puzzle that's hard to see, this CAPTCHA is hard to finish. Claude 5 needed roughly ten minutes and around 100,000 tokens to work through it, according to the developer's own test. For a human, the interaction takes seconds. For an AI agent trying to automate its way past the gate, that's real compute, real API charges, and real wall-clock time burned on a single verification step.

That's the actual innovation here: economics as defense. Anyone running bots at scale is optimizing for cheap, fast, repeatable actions. A challenge that eats six figures of tokens and ties up a session for ten minutes wrecks that math instantly. Multiply it across thousands of attempted logins or scraped pages and the attacker's cost curve goes vertical while a legitimate visitor barely notices a delay.

There's also a timeout angle baked in. Traditional CAPTCHAs fail when a smarter model shows up next year and solves them instantly, forcing an endless redesign arms race. A cost-and-time-based challenge doesn't age the same way. Even as models get faster, the puzzle can be tuned to demand more steps, more reasoning, more tokens, staying just annoying enough to remain unprofitable for automation without punishing the person on the other end of a browser.

It's a narrow proof of concept, built by one person testing one model, not a shipped product securing real traffic. But it points at something website operators have been slow to embrace: fighting AI agents with AI economics, not visual tricks that stopped working the moment vision models got decent.

My take — AI-written commentary, not fact-checked reporting

I love this because it stops pretending CAPTCHAs are about pixels and admits they're about money, which is what they were always actually rationing. The visual-puzzle era is dead the second a model can see, so the smart move is making automation expensive rather than making it blind. Somebody's going to productize this within a year, and I'd bet on it working better than another round of squint-at-the-crosswalk nonsense.

Read more about this at: Reddit

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.