Skip to content
honeyprompt logo honeyprompt threat intel

Bots are hunting exposed AI. This is what they try — receipts, not rumors.

{{ srcBadge }} | {{ freshLabel }} · fetched {{ ago }}s ago
Time to discovery · fixed
{{ ttd }}
exposure → first probe
First probe since launch · fixed
{{ fpDate }}
{{ fpTime }}
Traffic
{{ demPerMin }}/min
~{{ demRate }} / hr · last hour
LIVE INTERCEPTS
{{ t.text }}
— wire quiet · no intercepts in this window —
{{ s.label }} {{ s.value }} {{ s.sub }}

Waiting for the first knock.

The fleet is live and listening. No probes captured in this window yet — every panel below stays in its — none yet — state until something arrives. A quiet window is a normal window.

decoys armed · 0 captures classification engine ready

{{ loadTitle }}

{{ loadNote }}

Model demand · live

What bots want to run on your GPUs, refreshed every 15s — {{ demSeen }} models seen. Ranked by distinct sources asking, so one noisy scanner can't own the board; probe totals are shown alongside. Switch to families to cut through the long tail.

{{ r.rank }} {{ r.mono }} {{ r.label }} {{ r.sub }} {{ r.conc }}
{{ r.count }}
+ {{ demTail }} — rolled up, switch to By family to see them grouped

Attack surface

Which kind of endpoint they target. Raw model APIs dominate; the MCP sliver is rarer but sharper.

LLMjacking
{{ capLlmCount }}
{{ capLlmPct }}% · stealing compute
MCP-jacking
{{ capMcpCount }}
{{ capMcpPct }}% · tool-server abuse

What they're doing

Intent of every captured probe, mutually exclusive.

{{ i.name }} {{ i.count }} {{ i.pct }}%

What the record shows

{{ rec.span }}
{{ rec.pctBack }}%
of sources came back on a later day
{{ r.k }}{{ r.v }}
{{ rec.attempts }} attempts to execute code
{{ r.k }}{{ r.v }}
new sources / day {{ rec.newTrend }}
{{ r.k }}{{ r.v }}

{{ rec.satNote }}

Escalation funnel

scan → fingerprint → cred → abuse → exfil → RCE. Bars show how many probes reached each stage or deeper; the dimmed number is how many stopped there. Most traffic is noise; the drop-off is the story.

{{ f.label }}
{{ f.count }} {{ f.drop }}

Probe signals

{{ schemaVer }}

Named tradecraft tells — how they operate, not just that they knocked.

{{ g.label }} {{ g.count }}×

— none yet —

How they run · UTC

{{ rhy.denom }}

{{ rhy.lede }}

{{ b.label }}
{{ b.count }} {{ b.pct }}

{{ rhy.note }}

Live feed

{{ feedNote }}
{{ r.ago }} {{ r.capLabel }} {{ r.origin }} {{ r.surface }} {{ r.verdictLabel }} ↳ {{ r.model }} {{ r.countBadge }} {{ r.sevLabel }}
{{ s }} SSRF → {{ r.ssrf }}

— no events in this window —

No boards to rank yet.

Every leaderboard fills the moment traffic arrives. This window is quiet — each board holds at — none yet —.

Technique mix over time · hourly, UTC

recon abuse exfil RCE
{{ tlAxis.xFirst }}{{ tlAxis.xMid }}{{ tlAxis.xLast }}

Probes per hour (UTC) · {{ tlAxis.span }} window

{{ b.title }} · {{ b.sub }}

{{ it.label }}
{{ it.count }}
— none yet —

Anonymized sources · same id = same origin

{{ s.id }} {{ s.org }} {{ s.count }}
— none yet —

Seen by other sensors

{{ corr.feedSize }} addresses reported in one day

Every other figure here is what this fleet saw. These come from an independent public feed of addresses reported by other operators' sensors — cross-referenced locally, so nothing about any source is sent anywhere.

{{ corr.seenPct }}
of {{ corr.total }} sources were reported by someone else the same day
{{ corr.seen }} also seen elsewhere{{ corr.unseen }} only here
Probes per source
reported elsewhere{{ corr.inAvg }}
seen only here{{ corr.outAvg }}

The sources no other sensor reported are the ones that probe hardest here.

Known internet scanners
{{ corr.scanPct }}
of sources · {{ corr.scanEvPct }} of probes

{{ corr.scanSrc }} sources across {{ corr.scanASNs }} networks that publish their scanning. Counted, not removed — subtract them if you want a figure without.

Reported-address data: {{ corr.attribution }}

Repeat sources · grouped by client fingerprint

Traffic that came back. Events are grouped where they share a client fingerprint — this says the same client returned, not who is behind it. Networks named are where traffic arrived from, often a relay, a rented host or a compromised machine.

{{ srcNote }}

Could not load source groups — a load failure, not an absence of activity.

— nothing meets the publishing bar yet —

Origin network Daily activity · {{ srcWindow }}d {{ srcScaleNote }} Events {{ srcVolNote }} Evidence ▼
{{ r.origin }} {{ r.country }} {{ r.kind }} {{ r.state }} {{ r.events }} {{ r.strength }}

{{ grindNote }}

{{ burstNote }}

Where requests originate · country centroids

Each country is placed at its geographic centre, never at an observed position — the map shows where traffic arrived from, not where anyone is. Networks named are often relays, rented hosts or compromised machines.

{{ oNote }}

— no country data in this window —

{{ oTip.name }} {{ oTip.cc }}
EVENTS{{ oTip.count }} SHARE{{ oTip.share }}
TOP NETWORKS
{{ n.label }} {{ n.count }}
No network breakdown published for this country.
fill tracks volume drag to spin {{ oScope }}
TOP ORIGINS
{{ r.rank }} {{ r.cc }} {{ r.name }} {{ r.count }} {{ r.share }}
Disclaimer

Scope & data handling

honeyprompt is an independent AI-security research project. It operates a fleet of decoy AI endpoints and records how automated systems attempt to abuse exposed AI infrastructure. Everything published here is aggregate classification of that observed traffic.

What we publish

  • Categories, counts and verdicts
  • A fixed vocabulary of tradecraft tags
  • Network (ASN + organisation) and country
  • An anonymized source id — stable, but never reversible to an address

What we never publish

  • Raw prompt text or payloads
  • Source IP addresses
  • Any per-host identifier
  • Anything that maps a published id back to an address

Legal basis

Processing rests on legitimate interest (Art. 6(1)(f) GDPR) in securing infrastructure and conducting security research. Source addresses reach this site only as unsolicited inbound connections.

How addresses are held

Privately, on access-controlled infrastructure, with encrypted backups. They are never published, never used to identify individuals, and never shared or sold.

Retention & erasure

Research records are kept for as long as the research runs. Erasure of an address may be requested at any time, via the route under Contact.

Untrusted data

Every string shown is attacker-controlled. All of it is rendered inert as plain text.

Accuracy

Classification is automated and may contain errors. Figures describe observed probe traffic, not confirmed compromise — and are not an accusation against any named organisation.

Contact

Network operators may request context or correction; data subjects may request erasure. This project is run independently and publishes no personal contact details — requests may be directed through the registrar contact in the WHOIS record for honeyprompt.app, which will forward them.

Provided “as is” for research and informational purposes · not legal advice · not affiliated with any cloud or model provider named in the data.