I use Cloudflare for everything. DNS, CDN, Zero Trust access, email routing. When their Miami router started telling the internet to route every internal IPv6 route - including prefixes belonging to Meta, and hundreds of other networks - through it on January 22, my first reaction was professional curiosity. My second was: I trust these people with my infrastructure, and this is the kind of mistake that BGP makes trivially easy.

An automated policy change removed the last prefix-list entries from a term in an export policy on a single router. In JunOS, when a policy term's from clause loses all its prefix-list constraints, the remaining match conditions - in this case, route-type internal - become the only filter. That made every IBGP-learned IPv6 route eligible for external advertisement. For 25 minutes, traffic destined for peers and providers got funneled through Cloudflare's Miami data center - a location that never expected to carry it. Cloudflare's own firewall filters dropped roughly 12 Gbps of it. The rest hit backbone links between Miami and Atlanta, causing congestion and packet loss for Cloudflare customers sharing those paths.

If you were on an IPv6 connection trying to reach an affected network, your packets took a detour through infrastructure not built to handle them. Best case: higher latency. Worst case: your traffic was silently dropped by firewall rules that had no reason to expect it. BGP believed the route was legitimate, so everyone else did too.

The fixes exist. RFC 9234 (BGP Roles) can prevent this class of leak locally, even without the neighbor's cooperation - but Cloudflare's postmortem says they're still "validating routing equipment vendors' implementation" before rollout. RPKI ASPA would let networks reject anomalous paths globally, but under 1% of autonomous systems have published ASPA records. The protocol that routes all internet traffic still runs on a trust-by-default model designed for a few hundred participants. We're at 80,000+ autonomous systems now.