Skip to content
honeyprompt logo honeyprompt threat intel

Bots are hunting exposed AI. This is what they try — receipts, not rumors.

{{ srcBadge }} | {{ freshLabel }} · fetched {{ ago }}s ago
Time to discovery · fixed
{{ ttd }}
exposure → first probe
First probe since launch · fixed
{{ fpDate }}
{{ fpTime }}
Traffic
{{ demPerMin }}/min
~{{ demRate }} / hr · last hour
LIVE INTERCEPTS
{{ t.text }}
— wire quiet · no intercepts in this window —
{{ s.label }} {{ s.value }} {{ s.sub }}

Waiting for the first knock.

The fleet is live and listening. No probes captured in this window yet — every panel below stays in its — none yet — state until something arrives. A quiet window is a normal window.

decoys armed · 0 captures classification engine ready

Model demand · live

What bots want to run on your GPUs, refreshed every 15s — {{ demSeen }} models seen. Ranked by distinct sources asking, so one noisy scanner can't own the board; probe totals are shown alongside. Switch to families to cut through the long tail.

{{ r.rank }} {{ r.mono }} {{ r.label }} {{ r.sub }} {{ r.conc }}
{{ r.count }}
+ {{ demTail }} — rolled up, switch to By family to see them grouped

Attack surface

Which kind of endpoint they target. Raw model APIs dominate; the MCP sliver is rarer but sharper.

LLMjacking
{{ capLlmCount }}
{{ capLlmPct }}% · stealing compute
MCP-jacking
{{ capMcpCount }}
{{ capMcpPct }}% · tool-server abuse

What they're doing

Intent of every captured probe, mutually exclusive.

{{ i.name }} {{ i.count }} {{ i.pct }}%

Escalation funnel

scan → fingerprint → cred → abuse → exfil → RCE. Bars show how many probes reached each stage or deeper; the dimmed number is how many stopped there. Most traffic is noise; the drop-off is the story.

{{ f.label }}
{{ f.count }} {{ f.drop }}

Probe signals

{{ schemaVer }}

Named tradecraft tells — how they operate, not just that they knocked.

{{ g.label }} {{ g.count }}×

— none yet —

When they hit · UTC, 7×24

{{ h }} {{ row.day }}

Top networks · where, coarse

Busiest {{ asnShown }} of {{ asnTotal }} networks seen.

{{ a.as_org }}
{{ a.count }}

Live feed

{{ feedNote }}
{{ r.ago }} {{ r.capLabel }} {{ r.origin }} {{ r.surface }} {{ r.verdictLabel }} ↳ {{ r.model }} {{ r.countBadge }} {{ r.sevLabel }}
{{ s }} SSRF → {{ r.ssrf }}

— no events in this window —

No boards to rank yet.

Every leaderboard fills the moment traffic arrives. This window is quiet — each board holds at — none yet —.

Technique mix over time · hourly, UTC

recon abuse exfil RCE

{{ b.title }} · {{ b.sub }}

{{ it.label }}
{{ it.count }}
— none yet —

Anonymized sources · same id = same origin

{{ s.id }} {{ s.org }} {{ s.count }}
— none yet —

SSRF targets · defanged · display-only, never fetched

{{ s.target }} {{ s.count }}×
— none yet —
Disclaimer

Scope & data handling

honeyprompt is an independent AI-security research project. It operates a fleet of decoy AI endpoints and records how automated systems attempt to abuse exposed AI infrastructure. Everything published here is aggregate classification of that observed traffic.

What we publish

Categories, counts, verdicts and a fixed vocabulary of tradecraft tags derived from observed requests — nothing more.

What we never publish

Raw prompt text or payloads; source IP addresses; any per-host identifier. Origins are reduced to network (ASN + organisation), country, and an anonymized source id — the same origin always maps to the same id, which is not published in any form that maps back to an address.

Untrusted data

All strings shown are attacker-controlled and are rendered inert as plain text. SSRF targets are defanged and are display-only — never links, never fetched.

Legal basis (GDPR)

Processing is carried out on the basis of legitimate interest (Art. 6(1)(f) GDPR) in securing infrastructure and conducting security research. Source addresses reach this site only as unsolicited inbound connections; they are retained privately for up to 90 days, then deleted, and are never published — what you see here is coarse network and country metadata plus a non-identifying source id. Retained data is not used to identify individuals and is not shared or sold.

Requests & corrections

Operators of a network listed here may request context or correction. Classification is automated and may contain errors; figures describe observed probe traffic, not confirmed compromise.

No warranty

This dashboard is provided “as is” for research and informational purposes. It is not legal advice and not an accusation against any named organisation.

Independent research · not affiliated with any cloud or model provider named in the data.