Microsoft Titan flaw exposed 17.3 trillion rows to a teen
Titan accepted unsigned login tokens, so a 16-year-old could query 17 databases holding 17.3 trillion rows. Microsoft fixed it and paid him $5,000.
3 min read

By the numbers
- rows in the databases Titan exposed
- 17.3T
- analytics databases reachable
- 17
- bug bounty Microsoft paid
- $5,000
- from report to lockdown
- 4 days
A 16-year-old security researcher who goes by Faav found that Microsoft's Titan analytics service accepted forged login tokens. The flaw gave him administrator access to 17 databases holding an estimated 17.3 trillion rows of data, CyberPress reports. Microsoft locked the service down on September 9, 2026, and paid him a $5,000 bug bounty. The cause was one of the oldest mistakes in web security: the service never checked the token's signature.
What went wrong in Titan
Titan is a Microsoft analytics platform. Like many web services, it uses JSON Web Tokens (JWTs) to know who is logged in. A JWT is a small pass that holds a username and a digital signature. The server is supposed to check that signature, because it proves the server itself issued the pass.
Titan skipped that check, iTnews reports. CyberPress says Faav set the token's algorithm field to "none," which declares that a token has no signature at all. He then changed the username claim to "admin." Titan accepted it.
Logging in as "admin" gave him user ID 1 and full administrator rights, iTnews reports. From there he could send SQL queries, the commands that read data from a database, as an administrator.
How much was exposed
The numbers are large because Titan sat in front of a lot of data. CyberPress lists what the researcher mapped:
| What he could reach | Count |
|---|---|
| ClickHouse database setups | 24 |
| Connected analytics databases | 17 |
| Unique table names | 9,863 |
| Estimated rows | 17,333,335,124,315 |
| Application accounts | about 25,000 |
| Microsoft employee email records | 17,990 |
| Employee organization records | 15,001 |
ClickHouse is an open-source database built for fast analytics on very large tables. VnExpress rounds the employee records to about 18,000.
Faav kept his footprint small. He pulled only two single-row samples during about 10 days of testing, iTnews reports.
The AI tool behind the find
Faav built an AI tool called Antares to do the repetitive parts of security research. CyberPress says Antares first flagged the flaw on August 25. The researcher then followed it up by hand.
"Antares wouldn't have gotten here alone, and neither would I," Faav said, as quoted by iTnews and VnExpress. He credits its persistence plus "one human hunch."
How Microsoft responded
The fix came fast once Microsoft knew. VnExpress gives the timeline below, and CyberPress matches its last two dates.
| Date (2026) | Event |
|---|---|
| August 25 | Antares flags the flaw |
| September 5 | Faav reports it to Microsoft |
| September 9 | Microsoft asks him to stop testing and locks down the API |
| September 17 | Microsoft awards the $5,000 bounty |
Microsoft thanked him in a statement. His report "helped us to better protect our customers by hardening our services," the company said, as quoted by VnExpress. The iTnews report adds that Microsoft gave editorial input on Faav's public write-up, including cut sections, redacted images and changes to how the impact was described.
What this means for developers
Check that every service you run verifies JWT signatures, and rejects tokens marked "none." Most JWT libraries do this by default, but a wrong setting or a hand-written parser can turn it off. Write a test that sends a token with the "none" algorithm and expects a rejection.
Pin the algorithm your server accepts. Do not let the token itself tell the server how to check it. GitHub's App installation tokens became JWTs on October 2, so more developers will be handling these tokens directly.
Treat analytics and admin tools as exposed. An outside researcher reached Titan's API with nothing but a forged token. Give back-office dashboards the same authentication tests as public apps, and do not let a single "admin" name unlock everything.
Expect more finds like this one. A teenager with a home-built AI tool found this flaw. Attackers can build the same kind of tool, so basic mistakes like a skipped signature check get found faster.
Sources
Related articles

Windows 11 turns on memory integrity by default from October 13
Microsoft will switch on Windows 11's kernel protection automatically on eligible PCs from the October 13 Patch Tuesday. Old drivers are the thing most likely to break.

Microsoft ThinkingBox grades AI agents by the database
Microsoft's ThinkingBox checks what an AI agent wrote to the database. 67.24% of 79,853 failed runs ended cleanly, with valid tool calls and wrong data.

Apple tightens macOS Full Disk Access over AI agents
Apple said on October 2 that Mac apps will need "very explicit user action" to get Full Disk Access, because AI agents make that access riskier.
The daily brief
Three to five stories a day, and what each one means for the people who build software. Free, no spam.