Is It Safe to Click ‘I’m Not a Robot’? Think Twice.

On the surface, clicking “I’m not a robot” seems harmless—after all, it’s a familiar step on many websites. But not every version of that button is what it appears to be.

While legitimate CAPTCHA systems are designed to protect you, cybercriminals have found ways to mimic them. When you click on a fake “I’m not a robot” prompt, you might unknowingly trigger a malicious script that copies itself to your clipboard. Moments later, you could be prompted to paste and run that code, often disguised as part of a verification process. That simple action—pasting a few lines into your browser or terminal—can give attackers access to your device, data, or accounts.

This isn’t just theory—it’s a growing tactic in phishing campaigns. Hackers embed these fake prompts on compromised or malicious sites, often luring users through misleading ads or search results. Once you interact, the damage can happen in seconds.

So how do you stay safe? First, pay attention to the website you’re on. If it looks off, loads strangely, or isn’t using a secure connection (https), proceed with caution. Second, never paste code into your browser or terminal unless you fully understand it and trust the source. Real CAPTCHA systems never require you to run scripts manually.

Staying alert is your best defense. Just because a button says “I’m not a robot” doesn’t mean the site isn’t trying to trick you. Always verify the legitimacy of a website before interacting with these prompts. In a world where scams are increasingly sophisticated, a split-second decision can have long-lasting consequences.

See also

In-depth articles

Related topics