On Friday 7 October 2022 at 19:52 UTC, a SYN flood targeted a crypto exchange customer in Central Europe. The attack peaked at 273.3 Gbps and lasted 60 minutes. Traffic originated from 316 autonomous systems in 68 countries, predominantly a rented booter service.
| Vector | SYN flood |
| Peak | 273.3 Gbps |
| Duration | 60 min |
| Time to mitigation | 0.275 s |
| Attack traffic reaching origin | 0.042% |
| Legitimate traffic challenged | 0.28% |
Timeline
The attack was preceded by a publicly announced sales event. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 12 points of presence.
What the customer saw
A brief increase in p99 latency of 108 ms during the first minute, then normal service.
Recommendations
- Lower challenge thresholds on authentication endpoints during high-risk events.
- Review allow-listed partner ranges quarterly.
- Add a dedicated rate limit for the targeted route.
Could you share the dataset behind the percentages?
Machine-readable ranges are at /ips.json and via the API.
Thanks — sharing this with our on-call team.
Verified good bots and allow-listed partners bypass challenges entirely.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
Great to hear, thanks for sharing your experience.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
Machine-readable ranges are at /ips.json and via the API.
This matches what we see in iGaming around big matches.
This matches what we see in iGaming around big matches.
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
Our auditors asked for exactly this kind of incident evidence under DORA.
Any plans to support per-tenant limits keyed on a JWT claim?