Smashing the token limit with overlapping fragments
Refract AI Intelligence Digest
BLUF
A new fragmentation method allows attackers and testers to exceed standard token limits for data exfiltration.
NEWS
PortSwigger researchers introduced a collaboration with Alex to demonstrate how overlapping fragments can circumvent token restrictions. This advancement builds upon existing tools like DOM Invader to facilitate larger data extraction during security assessments.
Why I Care
Applications relying on token size limits for security controls may be vulnerable to increased data leakage, impacting both defensive postures and the efficacy of current scanning tools.
Next Steps
Security teams should audit token limit configurations and update web application firewalls to detect fragment-based anomalies by the end of Q4 2026.
I'm delighted to introduce Alex, my fellow swigger who I've collaborated with in the past with tools like DOM Invader. He showed me that it's possible to exfiltrate larger tokens than demonstrated in
Source: PortSwigger Research ·