Since Spectre first unsettled the computing world in 2018, security researchers have warned that shared hardware is borrowed trust. Now, in August 2026, that warning has taken concrete form: a demonstrated attack against Cloudflare Workers extracts authentication tokens from neighboring applications by listening to the whispers of CPU cache timing, achieving what was once dismissed as impractical at a quiet but consequential 12 bits per second. The discovery does not merely expose one platform's gap — it surfaces a deeper tension at the heart of serverless computing, where the economics of den
Cloudflare Workers Vulnerable to Spectre Attack Leaking JWT Tokens
Attackers can extract tokens in under a minute of continuous probing
So this is a Spectre attack, which we've known about for years. Why does it matter that it works on Cloudflare Workers specifically?
Because Cloudflare Workers is multi-tenant—dozens or hundreds of different customers' code runs on the same physical CPU. Spectre lets you peek at what your neighbor is doing. In a traditional server you own, that's not a problem. Here, your neighbor might be an attacker.
And they're stealing JWTs. Why are those tokens so valuable?
A JWT is basically a signed credential. If I steal yours, I can pretend to be your application when I talk to your backend systems. I can read your data, modify it, do whatever your app is allowed to do.
Twelve bits per second sounds slow. Is that actually a threat?
It sounds slow until you do the math. A typical JWT is 500 to 1000 characters. At 12 bits per second, you're looking at a few minutes to steal a complete token. That's practical. An attacker just needs to keep a worker running alongside you.
Could Cloudflare just separate everyone's code better?
Yes, but that's the whole tradeoff. Separation—containers, VMs—costs money and adds latency. That's why serverless is cheap. The more you isolate, the less efficient it becomes.
So what happens now?
Cloudflare will probably have to choose between accepting the risk, implementing expensive isolation, or finding some middle ground. And every other serverless platform faces the same choice.
Il Polso
- A working Spectre exploit now allows a malicious Cloudflare Worker to silently drain JWT authentication tokens from co-located tenants, turning shared infrastructure into a surveillance opportunity.
- At 12 bits per second, the attack is slow enough to seem harmless but fast enough to steal a complete authentication token in under a minute of quiet, undetected probing.
- The attack costs an adversary almost nothing — deploying a Cloudflare Worker is cheap and trivial, meaning the barrier to mounting a cross-tenant espionage campaign is dangerously low.
- Cloudflare has issued no patch or public statement, and the isolation mechanisms already in place appear insufficient against an attacker who understands Spectre techniques.
- The vulnerability almost certainly extends beyond Cloudflare — Amazon Lambda, Google Cloud Functions, and Azure Functions share the same architectural assumptions and face comparable exposure.
- The industry is now being pushed toward costly remedies: per-tenant containers, microcode updates, or hardware-level isolation — each of which trades away the speed and economy that made serverless computing attractive.
Since Spectre first unsettled the computing world in 2018, security researchers have warned that shared hardware is borrowed trust. Now, in August 2026, that warning has taken concrete form: a demonstrated attack against Cloudflare Workers extracts authentication tokens from neighboring applications by listening to the whispers of CPU cache timing, achieving what was once dismissed as impractical at a quiet but consequential 12 bits per second. The discovery does not merely expose one platform's gap — it surfaces a deeper tension at the heart of serverless computing, where the economics of density and the demands of security have always pulled in opposite directions.
Researchers have demonstrated a practical, working attack against Cloudflare Workers that uses the long-feared Spectre vulnerability to steal JWT authentication tokens from neighboring applications sharing the same physical hardware. The technique exploits CPU cache timing — measuring how long it takes to retrieve data from memory to infer what secrets a co-located application is holding — and achieves exfiltration at 12 bits per second.
While that rate sounds slow, it is fast enough to extract a complete authentication token in under a minute. JWTs are high-value targets because they carry credentials that grant access to backend systems and user data; a stolen token allows an attacker to impersonate a legitimate application entirely. The cost of mounting the attack is minimal, since deploying a Cloudflare Worker is inexpensive and requires no special access.
The finding exposes a structural tension that serverless computing has never fully resolved. Cloudflare Workers runs many customers' code on the same machines — a model that drives efficiency and low cost, but that also means the security boundary between tenants must be absolute. The research shows it is not. Cloudflare has not issued a public statement or patch, and its existing isolation mechanisms appear insufficient against a knowledgeable attacker.
The problem is not Cloudflare's alone. Spectre exploits fundamental properties of modern CPU design — speculative execution and shared caches — that are difficult and costly to fully mitigate. Other major serverless platforms face structurally similar risks. The discovery is likely to accelerate industry conversations about stronger isolation models, whether through per-tenant virtual machines, specialized CPU instructions, or microcode updates, though each remedy carries performance and cost penalties that the serverless model was specifically designed to avoid.
Researchers have demonstrated a working attack against Cloudflare Workers that exploits the Spectre vulnerability to steal authentication tokens from neighboring applications running on the same hardware. The attack works by leveraging CPU cache timing differences—a technique that has haunted processor design since Spectre became public knowledge in 2018. What makes this particular discovery significant is that it shows the vulnerability isn't merely theoretical in the serverless context; attackers can extract JSON Web Tokens, or JWTs, at a rate of 12 bits per second from co-located worker instances.
Cloudflare Workers is a platform that allows developers to run code at the edge of Cloudflare's global network, closer to end users. The service is built on shared infrastructure, meaning many different customers' applications run on the same physical machines. This multi-tenant model is central to the platform's efficiency and cost structure, but it also creates a potential security boundary that needed to hold. The researchers found it does not.
The attack works by having a malicious worker instance probe the CPU cache to infer what data a neighboring worker is accessing. By measuring the time it takes to retrieve information from memory, an attacker can determine whether that data is cached—and therefore what secrets a co-located application might be holding. JWTs are particularly valuable targets because they often contain authentication credentials that grant access to backend systems and user data. Once extracted, a stolen token could allow an attacker to impersonate the legitimate application.
The 12 bits-per-second extraction rate, while slow, is fast enough to be practical. A typical JWT might be several hundred characters long, meaning an attacker could potentially steal a complete token in under a minute of continuous probing. The attack requires the attacker to maintain a worker instance running alongside the target, but given how inexpensive and easy it is to deploy code to Cloudflare Workers, this is not a significant barrier.
This discovery sits at the intersection of two long-standing security challenges. Spectre itself has proven remarkably difficult to fully patch because it exploits fundamental properties of how modern CPUs work—specifically, their tendency to speculatively execute instructions and cache results before confirming those instructions should have run. Mitigations exist but often come with performance costs that chip manufacturers and operating system designers have been reluctant to fully implement. The second challenge is the inherent tension in serverless computing: the entire value proposition depends on packing many customers' code onto shared hardware, but that density creates opportunities for one tenant to spy on another.
Cloudflare has not yet issued a public statement about the vulnerability or any patches. The company does offer some isolation mechanisms between workers, but the research suggests these may not be sufficient against a determined attacker with knowledge of Spectre techniques. Other serverless platforms—Amazon Lambda, Google Cloud Functions, Microsoft Azure Functions—likely face similar risks, though the specific implementation details vary.
The discovery will probably accelerate conversations within the industry about stronger isolation models. Some possibilities include running each worker in a separate container or virtual machine, which would eliminate the shared cache that Spectre exploits, though this would increase latency and cost. Another approach involves using specialized CPU instructions or microcode updates to prevent the speculative execution that enables the attack in the first place. For now, the research serves as a reminder that the convenience of serverless computing comes with security tradeoffs that are still being discovered and understood.