Researchers detail an AI model that they claim can solve Google's reCAPTCHAv2 challenges with 100% accuracy using a similar number of attempts as human users
Researchers from ETH Zurich used advanced machine learning to solve 100% of Google's reCAPTCHAv2, designed to distinguish humans from bots.
Context & Ripple Effects
This result extends a long-running contest between automated defenses and machine learning: Google had already moved toward invisible reCAPTCHA checks that assess users without a checkbox, while Vicarious researchers had previously reported a technique for solving CAPTCHAs with less training data.
The significance is not simply another benchmark. A human-versus-bot test only works while automated systems cannot reliably match the behavior it treats as human; the claimed result puts that assumption under fresh pressure.
First-order effects
- If reproducible, the ETH Zurich result gives Google evidence that reCAPTCHAv2's image challenges can no longer be treated as a dependable standalone bot filter.
- Sites using reCAPTCHAv2 inherit that exposure: attackers may be able to automate flows that the challenge was meant to slow, while legitimate users still bear the friction of completing it.
Second-order effects
- Google and relying services face pressure to add or emphasize signals beyond challenge solving—such as less visible risk assessment—rather than depending on image-recognition tasks alone.
- The result raises the value of continuous validation and adversarial testing, particularly because earlier CAPTCHA-solving research had already shown machine-learning approaches could reduce the training burden.
Third-order effects
- If such performance generalizes beyond this research setup, CAPTCHA design will continue shifting from static human-recognition puzzles toward layered, adaptive assurance systems—and away from tests that can be benchmarked as a vision task.
- That shift creates a recurring trade-off: stronger bot defenses may rely more on opaque signals, while providers must preserve reliable access for legitimate users and keep testing defenses against improving models.
The trend: This is one data point in the AI-driven erosion of challenge-based bot defenses, pushing online security toward adaptive, multi-signal verification.