Are you familiar with Attack on Titan? It's a story where humanity lives in cities surrounded by giant walls to fend off Titans. The walls are built to block known Titan paths, but what if Titans found an unexpected way in? Browsers, like the cities' defenders, heavily depend on the Content-Type in HTTP response headers to render content. But can we truly trust this Content-Type? Our investigation into S3 and S3-compatible object storage revealed a critical vulnerability: these storages allow any Content-Type to be specified in response headers, creating a new attack vector for clients, much like Titans finding an unforeseen breach. Specifying arbitrary Content-Type strings in HTTP response headers during file uploads was difficult. As a result, browsers and clients often trusted the Content-Type blindly, just as humanity trusted their walls. However, with the rise of object storage, setting arbitrary Content-Type headers has become easy. In this talk, we'll explore scenarios where clients' blind trust in Content-Type leads to vulnerabilities and share findings from bug bounty platforms and OSS investigations. Prepare to defend your web applications from these new threats!