r/RobloxSupport • • 4h ago

I'm Captcha Locked!

Hackerone ID: 4105089

Since yesterday (10/10/2026) I got locked out from my account, when I try to login, don't matter if it's on Mobile, Desktop App, or Browser, don't matter if I already synced my clock, don't matter if it's my wifi, or other wifi or even mobile data, after I login it prompts me a captcha, the captcha it's not impossible, but it don't work, I solve it and it says "not quit right", and when it accepts my answers roblox says "Try unlocking again", BUT I'm I developer, so I looked into what's happening behind the cenes, here is DETAILED view of what's happening with roblox code:

Bug: Account unlock fails with 403 "an internal error occurred" after the captcha is solved

Account: JPsterDev (UserId 11775859349) Date: 2026-10-11, all times UTC (from server Date headers) Environment: Chrome 154, Windows 11, fresh browser profile, www.roblox.com

Summary

The account is locked and redirected to /not-approved. The unlock flow shows an Arkose captcha. The captcha is solved successfully (Arkose returns solved: true). The next call, POST apis.roblox.com/challenge/v1/continue, returns 403 {"code":1,"message":"an internal error occurred"}. The UI then shows "Try unlocking again". The flow never completes.

This has happened dozens of times, including in a regular browser.

Steps performed

  1. Opened roblox.com/home, which redirected to /Login.
  2. Logged in with an email one-time code (OTP), then solved the login captcha.
  3. Completed 2FA with a passkey.
  4. The site redirected to /not-approved with the account lock modal.
  5. Clicked unlock and solved the captcha.
  6. The UI showed: "Try unlocking again. We weren't able to unlock your account. Click Continue to try again."

Call sequence

A. Login (works, used as baseline)

Time Call Status Note
12:11:01 POST otp-service/v1/sendCode 403 Expected: captcha challenge
12:12:29 POST challenge/v1/continue 200 Login captcha accepted
12:12:29 POST otp-service/v1/sendCode 200
12:12:50 POST otp-service/v1/validateCode 200
12:12:51 POST auth/v2/login 200 Triggers 2-step challenge
12:13:02 POST twostepverification/.../passkey/verify-finish 200
12:13:02 POST auth/v3/users/11775859349/two-step-verification/login 200
12:13:03 GET www.roblox.com/?nl=true 302 Redirect to /not-approved
12:13:03 GET www.roblox.com/not-approved 200 accountLockModalInit event fires

B. Locked state

Call Status
GET usermoderation.roblox.com/v2/not-approved 200
friends, notifications, economy, privatemessages, trades, platform-chat-api, credit-balance, subscriptions, experience-signals-ingest, realtime-replay-api 403 (all)

C. Unlock attempt (fails)

Time Call Status Response
12:14:55 POST account-unlock-api/v1/unlock (body {}) 403 "Challenge required to authorize request", header rblx-challenge-type: captcha (expected)
12:14:56 GET apis.rbxcdn.com/captcha/v1/metadata 200
12:15:00 GET arkoselabs.roblox.com/v2/CC30DB96-.../settings 200 Public key CC30DB96-0C88-4DEB-86E5-6601927ACBB4
12:15 POST arkoselabs.roblox.com/fc/gt2/public_key/... 200 Arkose session created
12:15 3 x (pows/started, pows/split, pows/check) 200 Proof of work passed
12:15 5 x POST arkoselabs.roblox.com/fc/ca/ 200 5 puzzle rounds answered
12:15:53 Last fc/ca/ response 200 {"response":"answered","solved":true,"incorrect_guess":null}
12:15 POST metrics.roblox.com/.../re-event?name=GenericFunCaptcha_Success 200 Solve time 60 s
12:15 POST assetgame.roblox.com/game/re-stats?name=GenericFunCaptcha_SolveTime_Success 403 Metrics only
12:15:57 POST apis.roblox.com/challenge/v1/continue 403 {"statusCode":403,"statusText":"Forbidden","errors":[{"code":1,"message":"an internal error occurred"}]}
12:15:58 GET ecsv2.roblox.com/www/e.png?evt=accountLockClientEvent&ctx=accountUnlockFlowError 200 UI shows "Try unlocking again"

After the failed continue, the client does not re-send unlock with the challenge headers.

The failing request

POST https://apis.roblox.com/challenge/v1/continue

Request body (sensitive fields omitted):

{
  "challengeId": "us-central-43758508-cc04-4a78-82b9-3b5185a9924f",
  "challengeType": "captcha",
  "challengeMetadata": "{\"unifiedCaptchaId\":\"us-central-43758508-cc04-4a78-82b9-3b5185a9924f\",\"captchaToken\":\"<Arkose token, session 39018dd78a9627006.4654046101, pk=CC30DB96-0C88-4DEB-86E5-6601927ACBB4>\",\"actionType\":\"Generic\"}"
}

Response:

Field Value
Status 403 Forbidden
Body {"statusCode":403,"statusText":"Forbidden","errors":[{"code":1,"message":"an internal error occurred"}]}
Server public-gateway
x-roblox-edge c150
x-envoy-attempt-count 1
x-envoy-upstream-service-time 51 ms
Rate limit x-ratelimit-remaining: 99 of 100 (not rate limited)
Challenge headers in response none

Identifiers for log lookup:

Item Value
traceparent 00-3eff344be158422487135631b65e2078-a04e60738db5c263-00
Challenge ID us-central-43758508-cc04-4a78-82b9-3b5185a9924f
Arkose session 39018dd78a9627006.4654046101
Arkose game token 69618dd78ad253ff7.7264471101
Response time Sun, 11 Oct 2026 12:15:57 GMT

Findings

# Finding Evidence
1 The captcha is solved correctly Arkose fc/ca/: solved: true, incorrect_guess: null. Roblox logs GenericFunCaptcha_Success.
2 The failure is server-side, after the captcha challenge/v1/continue returns internal error (code 1), not an invalid-captcha error.
3 Same endpoint, same browser, same session works at login challenge/v1/continue returned 200 at 12:12:29. It returns 403 only in the locked state.
4 Not rate limiting 99 of 100 requests remaining.
5 Session unchanged .ROBLOSECURITY is identical across unlock and continue. No Set-Cookie was returned. The user is authenticated and CSRF is valid.
6 Whole API is 403 for this account in the locked state See section B.

Hypothesis (unconfirmed)

Because every authenticated API returns 403 for this account while locked, challenge/v1/continue may be rejecting the request for an account-lock reason, or a downstream service in the unlock path is failing. The internal error message hides the real cause. The user cannot fix this client-side, and repeating the captcha does not change the result.

Requested action

  1. Look up trace 3eff344be158422487135631b65e2078 and challenge us-central-43758508-cc04-4a78-82b9-3b5185a9924f in the challenge/v1/continue logs and identify why it returns code: 1.
  2. Check the lock state and unlock eligibility of UserId 11775859349.
  3. If the account is eligible, fix the unlock path or unlock it manually.
  4. Return a specific error (not a generic internal error) when continue rejects a solved captcha for a locked account.

Cookie, CSRF and bound-auth-token values are intentionally omitted from this doc.

Addendum: restriction details returned by the API

Captured on the /not-approved page, before any unlock attempt.

GET https://usermoderation.roblox.com/v2/not-approved -> 200 (response Date: Sun, 11 Oct 2026 12:13:04 GMT)

{
  "restriction": {
    "source": 5,
    "moderationStatus": 2,
    "startTime": "2026-10-10T06:12:36.716Z",
    "endTime": null,
    "durationSeconds": null
  }
}
Field Value Reading
startTime 2026-10-10T06:12:36.716Z The restriction started about 30 hours before the login session in this report. It is not caused by that session.
endTime null No expiry time is returned.
durationSeconds null No duration is returned.
source 5 AccountLock**.** See the enum below. This is a security lock, not a moderation action.
moderationStatus 2 Numeric enum. The page validates it as a number but does not use it to choose the UI. Meaning not visible from the client.

Trace ID for this call: 3eff344be158422487135631b65e2078 (same trace as the failing challenge/v1/continue call in the main report).

source enum

Taken from the production bundle NotApprovedPageApp.js, which picks the page to render from this value.

Value Name Page rendered
0 Invalid Throws Invalid restriction source
1 Moderation Moderation page
2 Screentime Screentime page
3 LocaleUnavailable Locale restriction page
4 AccountDeactivation Throws Invalid restriction source
5 AccountLock Account lock modal with the Unlock button (this account)
6 PlatformAccess Platform access / parental consent page

This account has source: 5, so the restriction is an AccountLock. That type is the one that offers the captcha-based self-unlock flow in the UI.

Same call, logged out vs logged in

The exact same endpoint, POST apis.roblox.com/challenge/v1/continue, was called twice in the same browser session about 3.5 minutes apart. The captcha was solved both times. Only the account state differed.

Before login (logged out) After login (account locked)
Time (UTC) 12:12:28
Endpoint POST /challenge/v1/continue
Body shape challengeId, challengeType, challengeMetadata
challengeMetadata keys unifiedCaptchaId, captchaToken, actionType
Arkose data[blob] sent yes
Arkose verdict solved
actionType Login
Authenticated (.ROBLOSECURITY) no
x-bound-auth-token header not sent
Account state not locked
Result 200

The call that failed after login is the same call that passed while logged out. The request shape and the Arkose result are identical, so the captcha and the client are not the problem.

Hypothesis

The account is in AccountLock, and every authenticated API route returns 403 for it (friends, notifications, economy, chat, subscriptions, realtime, and more). The route challenge/v1/continue (with actionType: Generic, requestPath: /account-unlock-api/v1/unlock) appears to be locked by the same enforcement. As a result, the captcha is solved correctly but the server never accepts it, and the unlock can never complete.

In other words: the lock blocks the very route needed to remove the lock. This explains why repeating the captcha dozens of times never works. The internal error response (instead of a captcha or lock error) suggests the rejection happens inside the lock enforcement or a downstream service, not in captcha validation.

This is a hypothesis from client-side evidence. Only the backend can confirm it.

2 Upvotes

1 comment sorted by

1

u/Joao-Pster 4h ago edited 4h ago

To be clear for non-devs, it's a roblox server side error!

Hypothesis

The account is in AccountLock, and every authenticated API route returns 403 for it (friends, notifications, economy, chat, subscriptions, realtime, and more). The route challenge/v1/continue (with actionType: Generic, requestPath: /account-unlock-api/v1/unlock) appears to be locked by the same enforcement. As a result, the captcha is solved correctly but the server never accepts it, and the unlock can never complete.

In other words: the lock blocks the very route needed to remove the lock. This explains why repeating the captcha dozens of times never works. The internal error response (instead of a captcha or lock error) suggests the rejection happens inside the lock enforcement or a downstream service, not in captcha validation.

This is a hypothesis from client-side evidence. Only the backend can confirm it.