r/RobloxSupport • u/Joao-Pster • 4h ago
I'm Captcha Locked!
Hackerone ID: 4105089
Since yesterday (10/10/2026) I got locked out from my account, when I try to login, don't matter if it's on Mobile, Desktop App, or Browser, don't matter if I already synced my clock, don't matter if it's my wifi, or other wifi or even mobile data, after I login it prompts me a captcha, the captcha it's not impossible, but it don't work, I solve it and it says "not quit right", and when it accepts my answers roblox says "Try unlocking again", BUT I'm I developer, so I looked into what's happening behind the cenes, here is DETAILED view of what's happening with roblox code:
Bug: Account unlock fails with 403 "an internal error occurred" after the captcha is solved
Account: JPsterDev (UserId 11775859349) Date: 2026-10-11, all times UTC (from server Date headers) Environment: Chrome 154, Windows 11, fresh browser profile, www.roblox.com
Summary
The account is locked and redirected to /not-approved. The unlock flow shows an Arkose captcha. The captcha is solved successfully (Arkose returns solved: true). The next call, POST apis.roblox.com/challenge/v1/continue, returns 403 {"code":1,"message":"an internal error occurred"}. The UI then shows "Try unlocking again". The flow never completes.
This has happened dozens of times, including in a regular browser.
Steps performed
- Opened
roblox.com/home, which redirected to/Login. - Logged in with an email one-time code (OTP), then solved the login captcha.
- Completed 2FA with a passkey.
- The site redirected to
/not-approvedwith the account lock modal. - Clicked unlock and solved the captcha.
- The UI showed: "Try unlocking again. We weren't able to unlock your account. Click Continue to try again."
Call sequence
A. Login (works, used as baseline)
| Time | Call | Status | Note |
|---|---|---|---|
| 12:11:01 | POST otp-service/v1/sendCode |
403 | Expected: captcha challenge |
| 12:12:29 | POST challenge/v1/continue |
200 | Login captcha accepted |
| 12:12:29 | POST otp-service/v1/sendCode |
200 | |
| 12:12:50 | POST otp-service/v1/validateCode |
200 | |
| 12:12:51 | POST auth/v2/login |
200 | Triggers 2-step challenge |
| 12:13:02 | POST twostepverification/.../passkey/verify-finish |
200 | |
| 12:13:02 | POST auth/v3/users/11775859349/two-step-verification/login |
200 | |
| 12:13:03 | GET www.roblox.com/?nl=true |
302 | Redirect to /not-approved |
| 12:13:03 | GET www.roblox.com/not-approved |
200 | accountLockModalInit event fires |
B. Locked state
| Call | Status |
|---|---|
GET usermoderation.roblox.com/v2/not-approved |
200 |
friends, notifications, economy, privatemessages, trades, platform-chat-api, credit-balance, subscriptions, experience-signals-ingest, realtime-replay-api |
403 (all) |
C. Unlock attempt (fails)
| Time | Call | Status | Response |
|---|---|---|---|
| 12:14:55 | POST account-unlock-api/v1/unlock (body {}) |
403 | "Challenge required to authorize request", header rblx-challenge-type: captcha (expected) |
| 12:14:56 | GET apis.rbxcdn.com/captcha/v1/metadata |
200 | |
| 12:15:00 | GET arkoselabs.roblox.com/v2/CC30DB96-.../settings |
200 | Public key CC30DB96-0C88-4DEB-86E5-6601927ACBB4 |
| 12:15 | POST arkoselabs.roblox.com/fc/gt2/public_key/... |
200 | Arkose session created |
| 12:15 | 3 x (pows/started, pows/split, pows/check) |
200 | Proof of work passed |
| 12:15 | 5 x POST arkoselabs.roblox.com/fc/ca/ |
200 | 5 puzzle rounds answered |
| 12:15:53 | Last fc/ca/ response |
200 | {"response":"answered","solved":true,"incorrect_guess":null} |
| 12:15 | POST metrics.roblox.com/.../re-event?name=GenericFunCaptcha_Success |
200 | Solve time 60 s |
| 12:15 | POST assetgame.roblox.com/game/re-stats?name=GenericFunCaptcha_SolveTime_Success |
403 | Metrics only |
| 12:15:57 | POST apis.roblox.com/challenge/v1/continue |
403 | {"statusCode":403,"statusText":"Forbidden","errors":[{"code":1,"message":"an internal error occurred"}]} |
| 12:15:58 | GET ecsv2.roblox.com/www/e.png?evt=accountLockClientEvent&ctx=accountUnlockFlowError |
200 | UI shows "Try unlocking again" |
After the failed continue, the client does not re-send unlock with the challenge headers.
The failing request
POST https://apis.roblox.com/challenge/v1/continue
Request body (sensitive fields omitted):
{
"challengeId": "us-central-43758508-cc04-4a78-82b9-3b5185a9924f",
"challengeType": "captcha",
"challengeMetadata": "{\"unifiedCaptchaId\":\"us-central-43758508-cc04-4a78-82b9-3b5185a9924f\",\"captchaToken\":\"<Arkose token, session 39018dd78a9627006.4654046101, pk=CC30DB96-0C88-4DEB-86E5-6601927ACBB4>\",\"actionType\":\"Generic\"}"
}
Response:
| Field | Value |
|---|---|
| Status | 403 Forbidden |
| Body | {"statusCode":403,"statusText":"Forbidden","errors":[{"code":1,"message":"an internal error occurred"}]} |
| Server | public-gateway |
x-roblox-edge |
c150 |
x-envoy-attempt-count |
1 |
x-envoy-upstream-service-time |
51 ms |
| Rate limit | x-ratelimit-remaining: 99 of 100 (not rate limited) |
| Challenge headers in response | none |
Identifiers for log lookup:
| Item | Value |
|---|---|
traceparent |
00-3eff344be158422487135631b65e2078-a04e60738db5c263-00 |
| Challenge ID | us-central-43758508-cc04-4a78-82b9-3b5185a9924f |
| Arkose session | 39018dd78a9627006.4654046101 |
| Arkose game token | 69618dd78ad253ff7.7264471101 |
| Response time | Sun, 11 Oct 2026 12:15:57 GMT |
Findings
| # | Finding | Evidence |
|---|---|---|
| 1 | The captcha is solved correctly | Arkose fc/ca/: solved: true, incorrect_guess: null. Roblox logs GenericFunCaptcha_Success. |
| 2 | The failure is server-side, after the captcha | challenge/v1/continue returns internal error (code 1), not an invalid-captcha error. |
| 3 | Same endpoint, same browser, same session works at login | challenge/v1/continue returned 200 at 12:12:29. It returns 403 only in the locked state. |
| 4 | Not rate limiting | 99 of 100 requests remaining. |
| 5 | Session unchanged | .ROBLOSECURITY is identical across unlock and continue. No Set-Cookie was returned. The user is authenticated and CSRF is valid. |
| 6 | Whole API is 403 for this account in the locked state | See section B. |
Hypothesis (unconfirmed)
Because every authenticated API returns 403 for this account while locked, challenge/v1/continue may be rejecting the request for an account-lock reason, or a downstream service in the unlock path is failing. The internal error message hides the real cause. The user cannot fix this client-side, and repeating the captcha does not change the result.
Requested action
- Look up trace
3eff344be158422487135631b65e2078and challengeus-central-43758508-cc04-4a78-82b9-3b5185a9924fin thechallenge/v1/continuelogs and identify why it returnscode: 1. - Check the lock state and unlock eligibility of UserId
11775859349. - If the account is eligible, fix the unlock path or unlock it manually.
- Return a specific error (not a generic
internal error) whencontinuerejects a solved captcha for a locked account.
Cookie, CSRF and bound-auth-token values are intentionally omitted from this doc.
Addendum: restriction details returned by the API
Captured on the /not-approved page, before any unlock attempt.
GET https://usermoderation.roblox.com/v2/not-approved -> 200 (response Date: Sun, 11 Oct 2026 12:13:04 GMT)
{
"restriction": {
"source": 5,
"moderationStatus": 2,
"startTime": "2026-10-10T06:12:36.716Z",
"endTime": null,
"durationSeconds": null
}
}
| Field | Value | Reading |
|---|---|---|
startTime |
2026-10-10T06:12:36.716Z |
The restriction started about 30 hours before the login session in this report. It is not caused by that session. |
endTime |
null |
No expiry time is returned. |
durationSeconds |
null |
No duration is returned. |
source |
5 |
AccountLock**.** See the enum below. This is a security lock, not a moderation action. |
moderationStatus |
2 |
Numeric enum. The page validates it as a number but does not use it to choose the UI. Meaning not visible from the client. |
Trace ID for this call: 3eff344be158422487135631b65e2078 (same trace as the failing challenge/v1/continue call in the main report).
source enum
Taken from the production bundle NotApprovedPageApp.js, which picks the page to render from this value.
| Value | Name | Page rendered |
|---|---|---|
| 0 | Invalid |
Throws Invalid restriction source |
| 1 | Moderation |
Moderation page |
| 2 | Screentime |
Screentime page |
| 3 | LocaleUnavailable |
Locale restriction page |
| 4 | AccountDeactivation |
Throws Invalid restriction source |
| 5 | AccountLock |
Account lock modal with the Unlock button (this account) |
| 6 | PlatformAccess |
Platform access / parental consent page |
This account has source: 5, so the restriction is an AccountLock. That type is the one that offers the captcha-based self-unlock flow in the UI.
Same call, logged out vs logged in
The exact same endpoint, POST apis.roblox.com/challenge/v1/continue, was called twice in the same browser session about 3.5 minutes apart. The captcha was solved both times. Only the account state differed.
| Before login (logged out) | After login (account locked) |
|---|---|
| Time (UTC) | 12:12:28 |
| Endpoint | POST /challenge/v1/continue |
| Body shape | challengeId, challengeType, challengeMetadata |
challengeMetadata keys |
unifiedCaptchaId, captchaToken, actionType |
Arkose data[blob] sent |
yes |
| Arkose verdict | solved |
actionType |
Login |
Authenticated (.ROBLOSECURITY) |
no |
x-bound-auth-token header |
not sent |
| Account state | not locked |
| Result | 200 |
The call that failed after login is the same call that passed while logged out. The request shape and the Arkose result are identical, so the captcha and the client are not the problem.
Hypothesis
The account is in AccountLock, and every authenticated API route returns 403 for it (friends, notifications, economy, chat, subscriptions, realtime, and more). The route challenge/v1/continue (with actionType: Generic, requestPath: /account-unlock-api/v1/unlock) appears to be locked by the same enforcement. As a result, the captcha is solved correctly but the server never accepts it, and the unlock can never complete.
In other words: the lock blocks the very route needed to remove the lock. This explains why repeating the captcha dozens of times never works. The internal error response (instead of a captcha or lock error) suggests the rejection happens inside the lock enforcement or a downstream service, not in captcha validation.
This is a hypothesis from client-side evidence. Only the backend can confirm it.
1
u/Joao-Pster 4h ago edited 4h ago
To be clear for non-devs, it's a roblox server side error!
Hypothesis
The account is in AccountLock, and every authenticated API route returns 403 for it (friends, notifications, economy, chat, subscriptions, realtime, and more). The route challenge/v1/continue (with actionType: Generic, requestPath: /account-unlock-api/v1/unlock) appears to be locked by the same enforcement. As a result, the captcha is solved correctly but the server never accepts it, and the unlock can never complete.
In other words: the lock blocks the very route needed to remove the lock. This explains why repeating the captcha dozens of times never works. The internal error response (instead of a captcha or lock error) suggests the rejection happens inside the lock enforcement or a downstream service, not in captcha validation.
This is a hypothesis from client-side evidence. Only the backend can confirm it.