You’re Burning Your CPU to Stop AI Bots. You’re Just Making Them Stronger.

You’re sitting there, waiting for a webpage to load, watching a little spinner. Your laptop’s fan starts whirring like a jet engine. You aren’t rendering a 3D movie. You aren’t mining crypto. You’re just trying to prove you have a pulse to a server that thinks you might be a bot.

We have reached the dystopian peak of the internet: humans are forced to burn compute cycles just to prove they aren’t AI, while AI scrapers burn entire power grids to steal what we built.

You’ve probably noticed it. You click a link, and instead of the article, you get a “Verifying you are human…” screen. Anubis, the open-source proof-of-work (PoW) bot defender, spent a year shipping WebAssembly (WASM) to make this process smoother for you. The idea was simple: make real browsers solve a math problem fast enough that you don’t notice, but slow enough to bankrupt a scraping farm.

It sounds brilliant. It is a fatal flaw.

Every usability improvement on the client side also improves the solver side. The same WASM efficiency that makes PoW tolerable for humans makes it cheaper for AI-scale adversaries. When you optimize the math for a browser, you hand that exact optimized arithmetic to the bot farms. You didn’t build a wall; you paved a highway.

Optimizing proof-of-work for browsers doesn’t hurt the bots; it just makes their GPUs run cooler.

Look at the GitHub repos. The moment Anubis shipped WASM, developers pushed out browser extensions like pow-buster to accelerate the solver. If a random developer can write a WASM extension to bypass the wait, what do you think a company with 100,000 H100 GPUs is doing? They aren’t CPU-constrained. They aren’t even compute-constrained. They are memory-rich.

The thesis of Anubis is that scrapers are compute-limited in ways consumer devices are not. That was true in 2020. Today, AI companies are hoarding RAM and CUDA cores like doomsday preppers. As WASM makes PoW more viable in browsers, bots don’t give up. They move from CPU-constrained JavaScript to GPU/CUDA solvers. The bottleneck shifts from compute to memory. And AI companies own massive amounts of both.

You are playing chess against an opponent who can afford to buy the board, the pieces, and the building the tournament is held in.

Proof-of-work bot defense is not a settled technical fix. It is a perpetual economic and hardware arms race that will ultimately punish real users more than the bots it targets. We are taxing the innocent to subsidize the guilty. Next time your laptop fan spins up just to read a blog post, remember: you aren’t saving the internet. You’re just paying the toll for the AI companies to strip-mine it later.

FAQ

Q: Doesn't making the math harder for the bots hurt them eventually?

A: No. Bots aren't limited to browsers. They move from CPU-constrained JavaScript to GPU/CUDA solvers, shifting the bottleneck to memory, which AI companies have in abundance.

Q: What's the practical implication for web operators?

A: PoW defenses like Anubis are a temporary band-aid. If you operate a web service, don't rely on client-side compute to stop well-funded AI scrapers. They will always outspend your users.

Q: Is proof-of-work actually just a tax on the innocent?

A: Exactly. The hot take is that PoW defense forces real users to subsidize the cost of bot mitigation. You are burning your electricity to prove your humanity while AI companies strip-mine the web.

πŸ“Ž Source: View Source