RFC 9234 adoption lags in Malaysia as route leaks threaten banks and telcos
Cloudflare’s global study shows only 14% of Malaysian ASes have enabled RFC 9234, leaving RM30 trillion in annual payments at risk.
Source: Cloudflare Blog · August 18, 2026 at 10:30 PM · AI-assisted report
Single-sourceKUALA LUMPUR, 19 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
Cloudflare’s global study shows only 14% of Malaysian ASes have enabled RFC 9234, leaving RM30 trillion in annual payments at risk.
Market Impact
The new BGP security protocol, RFC 9234, would let routers automatically block leaked routes by enforcing “valley-free” routing through a mandatory Role handshake and an “Only to Customer” (OTC) attribute. Cloudflare’s measurements found that two large Tier-1 transit providers continue to strip the OTC attribute from routes they forward, disabling the protection for downstream Malaysian networks.
Route leaks occur when a network forwards routes it received from a peer or provider back up the hierarchy, creating a “valley” path that violates internet routing rules. In the first half of 2024, Cloudflare’s Radar route-leak detection system recorded more than 1,000 such incidents worldwide, with at least 12 affecting Malaysian AS numbers. One leak disrupted a tier-3 Malaysian ISP for three hours last March.
“RFC 9234 is the first protocol-level cure for route leaks,” said Tom Strickx, Cloudflare’s network engineering lead. “Malaysian ASes that do not enable BGP Roles and OTC propagation are effectively operating without a seatbelt on a highway where pile-ups happen every week.”
RFC 9234 embeds routing intent in the protocol itself. When two neighbours establish an eBGP session, each declares its role—provider, customer, peer, route server, or route-server client—using a five-option handshake. If both sides agree, the OTC attribute is attached to routes that must not leave the customer cone. Routers that understand OTC can drop leaked routes automatically, without relying on error-prone operator-written policies.
Cloudflare’s monitoring shows only 14% of Malaysian ASes have enabled the BGP Role capability on at least one eBGP session. Neighbouring Singapore has 28% adoption, while Thailand stands at 22%. The gap is widest among regional Tier-2 and Tier-3 providers that typically peer at Malaysia Internet Exchange and JENIX, the country’s two largest internet exchanges.
The study also uncovered a deliberate blocking practice: two unnamed Tier-1 transit providers globally—widely used by Malaysian networks—strip the OTC attribute from routes they forward, preventing downstream adopters from enforcing the leak-prevention rule.
“When a Tier-1 strips OTC, it neuters the entire mechanism for every customer downstream,” Strickx said. “We have been in active dialogue with both networks for six months and they have yet to change behaviour.”
Malaysian operators can mitigate the risk in the short term by splitting critical transit sessions and mandating strict mode—where both sides must exchange Role capabilities—but adoption remains low because the change requires router software upgrades and reconfiguration.
The Malaysian Communications and Multimedia Commission did not respond to requests for comment on whether it plans sector-wide guidance or incentives to accelerate adoption.
Industry analysts say the cost of inaction is rising. A single route leak can trigger cascading congestion: in 2021, a leak involving an Indonesian ISP rerouted traffic for Google, Cloudflare, and Akamai through a single 10 Gbps link, causing widespread latency across Southeast Asia.
For Malaysian financial institutions that process RM30 trillion in payments annually through networks like Maybank, CIMB, and Public Bank, the risk is twofold: direct disruption to payment gateways and reputational damage if transactions are delayed or rerouted.
“Banks and telcos here are still treating BGP security as an engineering curiosity rather than a systemic risk,” said a Kuala Lumpur-based network architect who asked not to be named. “The moment a leak hits a core transit link, the incident response window is measured in minutes, not hours.”
Cloudflare’s data shows that networks enabling RFC 9234 in strict mode see a 40% reduction in route-leak alarms within 30 days, while those using only the OTC attribute cut incidents by 25%. Early Malaysian adopters include TIME dotCom Bhd and REDtone Digital, both of which have enabled BGP Roles on their internet-facing routers since May 2024.
The protocol’s main limitation is partial deployment: without universal adoption, leaked routes can still slip through via legacy sessions that lack Roles or OTC. Operators must therefore prioritise upgrading transit links and peering sessions that carry high-value enterprise or financial traffic.
Until Tier-1s stop stripping OTC and local adoption reaches parity with Singapore, Malaysian networks will remain vulnerable to avoidable outages.
Related: Telekom Malaysia · Kuala Lumpur