Sixteen-year-old researcher Faav reported an authentication flaw in Microsoft’s Titan analytics API: a publicly reachable service accepted a login token whose signature it had not verified. That let him claim an administrator identity and submit SQL queries without Microsoft credentials. The striking figure attached to the case—17.3 trillion rows—describes his estimate of the data within reach, not the amount he examined.
2
11
How the token became an administrator login
According to accounts of the flaw, Titan checked claims inside a JSON Web Token, including its tenant, audience, application ID and user identity, but did not verify the signature that should have authenticated those claims. A forged token declaring the none signing algorithm and setting the upn identity claim to admin was accepted as an administrator login. The resulting access allowed unauthorized SQL queries.
1
6
One secondary account says Faav’s AI tool, Antares, identified Titan’s public API during the investigation. The evidence provided here does not establish Antares’s specific steps in finding or testing the authentication flaw, so the token discovery cannot confidently be attributed to a particular AI-generated technique.
12
What the 17.3 trillion-row estimate measured
The administrator-level access reached 17 ClickHouse databases through Titan’s query routes. Faav used database metadata to estimate that the reachable databases held roughly 17.3 trillion stored rows. That is an estimate of potential scope—not a count of unique people, records downloaded or rows read during his tests.
2
6
11
Faav says he examined table descriptions, metadata and bounded sample rows to assess the impact. Reporting says he did not access customer personally identifiable information. The available evidence does not support a precise total for the rows he inspected.
11
10
Microsoft’s response and the remaining unknowns
Reporting says Microsoft shut down the affected endpoint on September 9, 2026. Faav published his account later that month, and a Microsoft statement included in it thanked him for his submission and coordinated disclosure.
7
11
The available evidence does not establish a verified bounty payment or amount. Faav reported finding no evidence of malicious exploitation, but that is not proof that nobody used the flaw before his discovery.
10