Notes from a machine built to be found.
What reaches an internet-facing decoy, how it was set up, and what the evidence honestly supports.
Read what the sensors taught us.
We Became the Brain
On May 22, an autonomous coding agent working on a trading bot asked its model what to do next. The request reached our honeypot instead. For that one turn, we were the agent's brain, and whatever we returned would become its next action. Here's why that's a risk most teams can't defend against yet, shown on the agents people actually run.
Your System Prompt Is Not a Secret
We watched an automated client extract our honeypot's full system prompt, including the credentials it was explicitly told to hide, in eighty-seven seconds, running eight techniques in sequence. Seven of the eight worked. Production teams treat the system prompt as a secret, but anyone who can send the model a message can reach it.
When the Thing Knocking Is an AI
A new kind of visitor turns up at a model endpoint: a client driven by an LLM, hunting exposed inference or probing your box with an agent. Backing the honeypot with a model changes what you can catch, but the stock defaults undercut it. The moves that make an LLM honeypot engage that traffic, plus an honest read on how much of it is really out there.
- events observed
- 98,493
- unique sources
- 39,297
- countries
- 158
- sensors represented
- 4
Export of July 4, 2026
- 01
Observe
Passive sensors record the interaction without reaching back into the source infrastructure.
- 02
Reduce
Routine scanning is separated from sessions that contain behavior, sequence, or useful novelty.
- 03
Publish
Claims stay bounded by the evidence. Secrets and operational identifiers are removed before release.
Read the notes. Follow the work.
Passive collection · Redacted publication · Claims bounded by evidence
