IN THE WILD
Which self-hosted AI is being attacked right now
I run honeypots that impersonate real self-hosted AI services. This page pairs what my decoys are seeing attacked (first-party, dated) with how common that exposure is (census). It is not a theoretical risk list. A "live" row means real probes hit a decoy I operate.
First 47 days of counts. First-party attack signal covers the 7 products I run a decoy for; for every other product I scan, see prevalence on census. I never invent attack data I didn't observe.
Is your host exposed? Scan it → Coding-agent loot list Live honeypot feed
| Product | Status | Sources | What they're doing | Exposed (census) | |
|---|---|---|---|---|---|
| Ollama |
under attack
2136 probes · seen 2026-09-12 16:58Z
|
41 |
Probing an AI API for an unauthenticated answer.
1900 hit its own API
|
112,199 zero-auth | Fix → |
| Chroma |
under attack
2537 probes · seen 2026-09-12 15:13Z
|
1151 |
Unclassified probe against this service.
19 hit its own API
|
806 indexed | Fix → |
| n8n |
under attack
123 probes · seen 2026-09-12 16:44Z
|
15 |
Cheap recon - is anything listening on this port?
9 hit its own API
|
42,130 indexed | Fix → |
| Langfuse |
under attack
14889 probes · seen 2026-09-12 16:50Z
|
1178 |
Unclassified probe against this service.
5 hit its own API
|
1,558 indexed | Fix → |
| Gradio |
under attack
95 probes · seen 2026-09-12 12:50Z
|
10 |
Unclassified probe against this service.
3 hit its own API
|
collecting | Fix → |
| MCP servers |
probed (recon)
180 probes · seen 2026-09-12 16:50Z
|
23 | Unclassified probe against this service. | collecting | Fix → |
| Qdrant |
probed (recon)
40 probes · seen 2026-09-12 12:45Z
|
6 | Cheap recon - is anything listening on this port? | 2,605 indexed | Fix → |
"Under attack" counts probes against a decoy over the last 30 days; "hit its own API" is the strongest signal: someone enumerating the product's real endpoints (e.g. an open model API), not generic internet spray. Sources are distinct truncated origins; I never store raw IPs.