8 facts Your money Check FAQ
Mitilena Mitilena Wallet Cold crypto wallet
ONLINE · 22,000+ COINS Create walletCreate
How they fooled you all

Cloudflare: the story of one company that knows all your logins and secrets - under the guise of caring for you

For twenty years they taught you: if there is a lock - the connection is secure, enter your password. They did not say one thing: on seven of the ten largest sites in the world the lock leads not to the site, but to someone else's server, and most often that server is Cloudflare. There your login, password, cookie and messages are decrypted, read, run through filters and re-encrypted. This is not a hack and not an outage - this is their business, «site protection». Amazon, Akamai and Azure do the same - almost the entire internet is buried in this. Nobody asked you.

7 of 10largest sites in the world - behind a middlebox, most often Cloudflare
5 of 5popular wallets we checked - the same
0times anyone asked if you agree
exchange.example/login
Connection is secure
Your data (for example, passwords or card numbers) cannot be read by others while being sent to this site.
false on
7 of 10 sites
What actually happens
The lock leads to a Cloudflare server. There the password is decrypted and read by their code. The site gets it second.
Sign in
Login
you@mail.example
Password
••••••••••••Cloudflare reads this
Sign in
server: cloudflare · cf-ray: 8d3a1f2c9e4b7a10-FRA
certificate issued to Cloudflare, not to the site
What the lock promises

Chrome spent years scaring you about sites without a lock. Now every site has one - and on seven of ten large sites it leads to a middlebox

The lock and HTTPS were invented for one reason: so that nobody between you and the site could read what you send. Your ISP, cafe Wi-Fi, a state on the wire - all see only ciphertext. Browsers spent years teaching you: no lock - do not enter a password.

Cloudflare is a proxy that sits between you and the site; Amazon CloudFront, Azure Front Door, Akamai and Fastly work the same way. To «mitigate attacks», the middlebox needs to see traffic in the clear. So your connection ends on its server: there the request is decrypted, checked against its rules, and only then sent to the site over a separate connection. Cloudflare's own docs call this TLS termination - «the point where HTTPS traffic is decrypted so Cloudflare can inspect it». Amazon, Azure and Akamai use the same name for the same point in their docs.

Technically this is a classic man in the middle. The only difference from an attack: the site owner signed up for it when they put the site behind the middlebox. Plan or settings do not remove this: while the site is behind a middlebox, encryption ends at the middlebox - on the free plan and on Enterprise alike. Nobody asked you, and the lock will not tell you.

What you think when you see the lock
Youbrowser
one cipher to the site
Site
What actually happens on a site behind a middlebox
Youbrowser
cipher
Middleboxplaintext
cipher
Site
Cloudflare Flexible, Full and Full (strict) modes, Azure Front Door «end-to-end TLS» and CloudFront «origin protocol» describe only the second hop. The first hop always ends at the middlebox.
Two certificates: the one you see is issued to the middlebox. The one on the origin you never see.
Eight facts

What this means in practice - from docs and dates

No judgments. Only Cloudflare's own documentation, its own incident reports and public write-ups - with dates, so every line can be checked.

Fact 01

Seven of ten largest sites - behind a middlebox

Per HTTP Archive 2025, 71% of the thousand most visited sites in the world serve even the HTML document through a middlebox; among the top 10,000 - 70%, among the top 100,000 - 62%. Who those middleboxes are: Cloudflare - 58% of such sites, then Amazon CloudFront (7%), Fastly (5%), Akamai (2%) and cloud load balancers. Counting all sites in the world, every third is behind a middlebox; Cloudflare alone - 26% of all sites and 85% of the reverse-proxy market.

Source: HTTP Archive, Web Almanac 2025, CDN chapter; W3Techs reverse-proxy report, update 24.09.2026
What this means for you
The larger the site, the more likely it is that your password is read not by it, but by its middlebox. The lock looks the same either way.
Fact 02

The WAF reads the body of every request - per the docs

Cloudflare rules «inspect the body of each incoming request», and the field http.request.body.raw in their rules language is «the unaltered HTTP request body». A login form is a request body. The login and password in it are plaintext.

Source: developers.cloudflare.com: WAF managed rules; ruleset-engine, field http.request.body.raw
What this means for you
This is not a vulnerability, it is a feature. Your password passes through Cloudflare's code on every login to every site behind it. What it does with that next is a question of trust, not of technique.
Fact 03

Cloudbleed, 2017: the middlebox's memory leaked into other responses

From 22 September 2016 to 18 February 2017 a bug in Cloudflare's parser mixed chunks of memory from one site into responses of another: headers, pieces of POST requests with passwords, cookies, API keys and tokens. Cloudflare counted 1.2 million hits; leaks landed in search caches - more than 80,000 pages cleaned. Press coverage named Uber, OkCupid, Fitbit.

Source: Cloudflare, incident report 23.02.2017 and impact assessment 01.03.2017; Google Project Zero, issue 1139
What this means for you
One bug at the middlebox - a leak across hundreds of thousands of sites at once. None of those sites did anything wrong.
Fact 04

November 2023: attackers entered Cloudflare with stolen keys

From 14 to 24 November 2023 attackers - Cloudflare calls them «nation-state» - with credentials stolen in the Okta breach worked inside Cloudflare's systems: Confluence wiki, Jira tracker, Bitbucket repos, 76 repositories downloaded. After that Cloudflare rotated more than 5,000 credentials and reviewed 4,893 systems.

Source: Cloudflare, «Thanksgiving 2023 security incident», 01.02.2024
What this means for you
The middlebox through which a quarter of the internet flows is the fattest target in the world. Someone already got in.
Fact 05

One switch for everyone

2 July 2019 - 27 minutes, one regex in the WAF, traffic dropped 82%. 21 June 2022 - 75 minutes, 19 data centers. 18 November 2025 - almost six hours, «worst outage since 2019»: X, ChatGPT, Spotify, Shopify, Coinbase went down. 5 December 2025 - another 25 minutes. 20 February 2026 - six hours, a BGP error. None of the outages was an attack.

Source: Cloudflare outage postmortems 02.07.2019, 21.06.2022, 18.11.2025, 05.12.2025, 20.02.2026
What this means for you
When the middlebox breaks, half the internet breaks at once, including exchanges. Exactly when you need to sell.
Fact 06

Cloudflare decides whether you are human

The site owner ticks a box - and access is decided not by them, but by Cloudflare's filter. Their docs admit a «challenge loop, when the challenge appears again and again», including because of VPNs and proxies. Since 2016 Cloudflare treats Tor as a separate «country» and claims 94% of requests from there are malicious; Tor Project answered about an «endless loop of CAPTCHAs» and a block of at least 80% of Tor addresses.

Source: Cloudflare, «The Trouble with Tor», 30.03.2016; developers.cloudflare.com, troubleshooting challenge loops; Tor Project, 01.04.2016
What this means for you
VPN, Tor or the «wrong» region - and you are «not human». The site did not block you. A middlebox you did not know about locked you out.
Fact 07

When a state fights the middlebox: the Russia case

In October 2024 Cloudflare enabled ECH encryption by default on free plans. On 6 November 2024 sites behind Cloudflare with ECH stopped opening for Russian ISPs; on 7 November CMU SSOP (a Roskomnadzor unit) called ECH a «means of bypassing restrictions» and recommended that owners disable it «or, better, use domestic CDNs». Since 9 June 2025 the four largest Russian operators cut Cloudflare traffic to the first 16 KB of any file. Traffic from Russia fell about 30%; more than 40% of Russian-web sites - about 300,000 - sit behind Cloudflare. On 2 June 2026 the FSB announced that foreign intelligence services had been collecting data from Russian officials' phones «using the technical capabilities» of Cloudflare and Fastly, and opened cases under Criminal Code articles 272 and 273 - it showed no technical evidence, and the companies did not reply. The same Cloudflare has since 2022 covered UK Ministry of Defence sites under a government contract - Army, Royal Navy, RAF and the Defence Gateway portal for 330,000 users: £425k for 2022-2025 and £105k for 2025-2026.

Source: Interfax and RBC, 07.11.2024; Habr, 06.11.2024; Cloudflare, 26.06.2025; Kommersant, 19.06.2025; RIA Novosti, Mediazona and The Record, 02.06.2026; UK Contracts Finder notices of 25.01.2024 and 11.11.2025
What this means for you
«The site won't open» is often not the site. It is a middlebox you did not know about that fell out with your ISP.
Fact 08

Same scheme everywhere: Amazon, Akamai, Azure, Fastly

Any proxy or cloud load balancer that terminates TLS on itself works the same way: Amazon CloudFront and ALB, Azure Front Door and Application Gateway, Akamai, Fastly, Imperva. Each has its own WAF that reads the request body, its own cache and its own outages. Cloudflare is simply the largest and the most open in its documentation. Ordinary hosting with a certificate on the origin server is different: there only the site reads the traffic.

Source: AWS docs (CloudFront, Application Load Balancer), Azure Front Door, Akamai - TLS termination sections; W3Techs, September 2026
What this means for you
The question for any site with money is one: where does my cipher end - with you or with a middlebox? Below - how to check in a minute.
Your money

What this means for your money

Exchange behind a middlebox

Login, password, 2FA code, withdrawal address, trade history - all of that is request bodies the middlebox reads in plaintext. Plus a middlebox outage - and the exchange is down exactly when you need to sell: on 18 November 2025 Coinbase was among the sites that went down.

Web wallet behind a middlebox

Wallet code reaches your browser through the middlebox: whatever its server returned is what runs. That is the same «one line in the build» we wrote about in hardware-wallet flaws - only the point where it can appear is now also someone else's. Addresses you paste into forms it sees too.

Wallet with offline signing

The key lives on a device with no network, the transaction is signed there and goes online only as a signature. The middlebox has nothing to intercept, even if it were there: no password, no key, no code that decides where the money goes.
How we do it
Between you and any of our servers there is no middlebox. mitilena.com, api.mitilena.com, ru.mitilena.com answer directly: the certificate is ours, there is no cf-ray header in the responses. Our front server does not decrypt TLS - it looks only at the server name in the handshake and passes the stream as-is. What our server does see is broken down step by step on the page «How a wallet sends crypto». Checked 24.09.2026; you can repeat it in a minute - how is below.
Check

Check any site in a minute

You do not have to believe us or them. The middlebox leaves traces in every response, and anyone can see them.

01
In the terminalcurl -sI https://site/ and look at response headers. server: cloudflare and cf-ray - Cloudflare; via: 1.1 … cloudfront.net and x-amz-cf-id - Amazon; x-azure-ref - Azure Front Door; x-served-by: cache-… - Fastly; x-akamai-… - Akamai. Any of them means: TLS terminated at the middlebox, because a header can be added to the response only after decryption.
02
In the browserDevTools → Network → first request → Response Headers - the same headers. Or the lock → certificate: for Cloudflare the issuer is Google Trust Services WE1 for 90 days with no «organization» field; for Amazon the issuer is Amazon RSA 2048, meaning the certificate was ordered through AWS, not by the site itself; sites without their own domain show *.cloudfront.net. A certificate issued to the middlebox is its admission: the cipher ends with it.
03
By server addressping site or dig +short site - if the address is from published Cloudflare ranges (104.16.0.0/13, 172.64.0.0/13 and others), CloudFront, Azure Front Door or Akamai, all traffic goes through their servers. The hosting's own address - no middlebox.
terminal
$ curl -sI https://site.example | grep -iE "server|cf-"
server: cloudflare
cf-ray: 8d3a1f2c9e4b7a10-FRA
# TLS terminated at Cloudflare: cf-ray header
# was added to the already-decrypted response
terminal
$ curl -sI https://mitilena.com | grep -iE "server|cf-"
server: nginx
# no cf-ray: nobody between you and the server
First output - what a site behind Cloudflare looks like; Amazon, Akamai and Azure have their own headers (list on the left). Second - ours, captured 24.09.2026.
While we wrote this article

We took five of the most popular wallets and looked at who sits between you and their site

We did not guess and did not read other people's reviews: we made ordinary requests to the sites, looked at response headers and certificates. The result is below, as-is.

Check 24.09.2026 · sites of five popular walletsHEADERS AND CERTIFICATES
WalletProxyDecryptionWhose lock
MetaMaskmetamask.io
behind Cloudflare · yescf-ray in response · yesCloudflare certificate: Google Trust Services WE1, 90 days, no organization
Trust Wallettrustwallet.com
behind Cloudflare · yescf-ray in response · yesCloudflare certificate: Google Trust Services WE1, 90 days, no organization
Exodusexodus.com
behind Cloudflare · yescf-ray in response · yesCloudflare certificate: Google Trust Services WE1, 90 days, no organization
Phantomphantom.com
behind Cloudflare · yescf-ray in response · yesCloudflare certificate: Google Trust Services WE1, 90 days, no organization
Ledgerledger.com
behind Cloudflare · yescf-ray in response · yesCloudflare certificate: Google Trust Services WE1, 90 days, no organization
5 of 5 · TLS ends at Cloudflarerepeat it yourself - takes a minute
What this means
Five of five. The lock you see on your wallet's site is issued not by the wallet, but by Cloudflare. Everything you type on those sites, and all the code they send to your browser, passes through a middlebox you did not choose. What it does with that is a question of faith, not of technique.
How we checked
A request to each site's homepage, server and cf-ray headers in the response, issuer and lifetime of the certificate behind the lock. Date - 24 September 2026; sites can change configuration any day, so repeat the check yourself: instructions above, one minute.
FAQ

What people ask after reading this far

What is Cloudflare in plain words?

A middlebox company: the site sends all its traffic through their servers, and they «protect» it. To «protect», they decrypt your connection on their side. That is how a quarter of all sites in the world work.

Does Cloudflare see my passwords?

Yes. The connection ends on its server, and filtering rules per the docs read the body of every request - a login form with username and password is exactly that request body. Whether it stores that and for how long is governed by its policies, which you cannot verify.

Why does the site ask me to confirm I am human?

That is not the site, that is Cloudflare. The owner turned on the check, and the middlebox filter decides: VPN, Tor, a «suspicious» region, an old browser - and you fall into a challenge loop. Cloudflare itself admits such loops in its documentation.

A site behind Cloudflare will not open in my country. What can I do?

When a country fights with a middlebox, users get VPN - or a site without a middlebox. Site owners have one real fix: remove Cloudflare from between themselves and their users. The Russia case in Fact 07 shows how fast «the site is down» becomes «the middlebox fell out with the ISP».

Is this only about Cloudflare?

No. Any middlebox that terminates TLS on itself works this way: Amazon CloudFront and AWS load balancers, Azure Front Door, Akamai, Fastly, Imperva. Among the thousand largest sites in the world, 71% sit behind a middlebox: Cloudflare - 58% of them, Amazon - 7%, Fastly - 5%, Akamai - 2%. Ordinary hosting is different: there the traffic and the certificate belong to the site itself.

I own a site. What should I do?

Decide which matters more: «protection from attacks» or the fact that your users' passwords do not pass through someone else's code. Plan and settings do not change this - on any plan the cipher ends at the middlebox. There is a compromise - a proxy that does not decrypt TLS and only forwards the stream by server name. That is how our front server works: protection from excess traffic stays, a plaintext middlebox does not.

A wallet with nobody between you and it

Key on a device with no network · no sign-up · what our server sees - on the page «How a wallet sends crypto»
Create wallet