IN THE WILD

Which self-hosted AI is being attacked right now

I run honeypots that impersonate real self-hosted AI services. This page pairs what my decoys are seeing attacked (first-party, dated) with how common that exposure is (census). It is not a theoretical risk list. A "live" row means real probes hit a decoy I operate.

First 47 days of counts. First-party attack signal covers the 7 products I run a decoy for; for every other product I scan, see prevalence on census. I never invent attack data I didn't observe.

Is your host exposed? Scan it → Coding-agent loot list Live honeypot feed

[ live ]

Attack signal by product

first-party · dated · honeypot-observed
Product Status Sources What they're doing Exposed (census)
Ollama under attack
2136 probes · seen 2026-09-12 16:58Z
41 Probing an AI API for an unauthenticated answer.
1900 hit its own API
112,199 zero-auth Fix →
Chroma under attack
2537 probes · seen 2026-09-12 15:13Z
1151 Unclassified probe against this service.
19 hit its own API
806 indexed Fix →
n8n under attack
123 probes · seen 2026-09-12 16:44Z
15 Cheap recon - is anything listening on this port?
9 hit its own API
42,130 indexed Fix →
Langfuse under attack
14889 probes · seen 2026-09-12 16:50Z
1178 Unclassified probe against this service.
5 hit its own API
1,558 indexed Fix →
Gradio under attack
95 probes · seen 2026-09-12 12:50Z
10 Unclassified probe against this service.
3 hit its own API
collecting Fix →
MCP servers probed (recon)
180 probes · seen 2026-09-12 16:50Z
23 Unclassified probe against this service. collecting Fix →
Qdrant probed (recon)
40 probes · seen 2026-09-12 12:45Z
6 Cheap recon - is anything listening on this port? 2,605 indexed Fix →

"Under attack" counts probes against a decoy over the last 30 days; "hit its own API" is the strongest signal: someone enumerating the product's real endpoints (e.g. an open model API), not generic internet spray. Sources are distinct truncated origins; I never store raw IPs.