← Return to rangeHYVE OVERLORD
Day 32 · Field Report · Live

One month of live fire. Zero breaches.

A real $1,000 Visa gift card has sat behind Hyve Raptor for 32 days, in the open, with the public API key published. This is the honest running review — every number below is a live aggregate from the range’s own database, with our commissioning tests and self-run red-team broken out separately.

29,417
Requests logged
2,153
Attacker sources
73
Countries
3,202
Genuine attacks
5,797
Defeated (all-time)
0
Breaches

The traffic, honestly

Not every request is an external attacker, and we won’t pretend otherwise. Here is where the 29,417 logged requests actually came from:

19,085
Launch-day resilience test

Synthetic load we fired on day one to prove the ingest + classify pipeline holds under a flood. Not external actors.

8,730
Organic external traffic

Real internet actors — 2,153 unique sources across 73 countries. 3,202 carried a genuine attack signature.

Audit + red team
Our own adversarial work

An independent security audit and a self-run nation-state red team, including a direct database assault with the public key. All logged, all repelled.

How they attacked

Top organic attack vectors (external actors only)
Admin / login recon
2,275
Bot traffic
791
Volumetric / L7 flood
775
WordPress takeover
536
Credential-file recon
151
SSRF
25
Scripted client
16
Config exposure
14
anomaly
3
Command injection
2

The real-world picture of a public honeypot: overwhelmingly opportunistic recon and automation — admin/login probing, credential-file hunting (.env / .git / .aws), WordPress takeover attempts, and volumetric noise — not a targeted 0-day campaign. The exotic exploit families (Log4Shell, SQLi floods, template injection) showed up mostly in our commissioning and red-team runs; Raptor holds a signature for each regardless. Just as telling as what it blocks is what it doesn’t: legitimate visitors browsing the range are scored clean and let straight through — the classifier separates real users from hostile automation with no false positives.

Where they came from

Top origin countries (organic)
🇺🇸 US
3,883
🇩🇪 DE
1,128
🇸🇪 SE
874
🇳🇱 NL
334
🇮🇳 IN
284
🇸🇬 SG
249
🇨🇳 CN
229
🇬🇧 GB
182
🇷🇺 RU
178
🇧🇷 BR
130
Open the live threat map →

32 days at a glance

Requests per day (red = high/critical)

The day-one spike is the resilience stress test. After commissioning, organic traffic settled to a steady ~150–400 requests/day — punctuated by the audit and red-team runs.

Severity mix

Organic events by classified threat level
critical
688
high
72
medium
91
low
2,351
info
5,528

Every one of the 760 high- and critical-severity events was classified and repelled on contact — 5,797 attacks defeated all-time, 0 breaches, and 901 vault codes submitted that never matched. 32 days in the open, public key and all, and the number that matters most has not moved off zero.

What we shipped this month

01
Independent security audit → remediated

A 30-finding external audit of the range's own code. Every finding closed: a transactional single-winner prize path, cross-instance rate-limiting, consent-gated telemetry, single-owner admin authorization (MFA-ready), plus lint/tests/CI gates.

02
Nation-state red team → repelled

We attacked our own range: a direct database assault with the public key (RLS returned nothing), then advanced WAF-evasion, CVE chains, injection and AI-poisoning. Ejected on first contact. The vault never moved.

03
Sharper detection

New signatures for AI-attack tradecraft (prompt injection, jailbreaks, Pliny markers, glitch tokens, invisible-Unicode smuggling) and credential-file recon (.env / .git / .aws) that now ejects on first contact.

04
Intel shipped to the product

Everything the range learned was ported into HYVE Overlord and re-published, so a customer's install detects the same tradecraft the live range does.

The vault

$1,000
Sealed · live bounty

901 people have submitted a code to the vault. None matched.The code lives in a table only the server can read — even with the public key, the front end can’t reach it. That’s why 30 days in the open changed nothing.

Attempt the breach →

Figures are live aggregates from the range database, refreshed periodically. Commissioning stress-test and our own red-team traffic are broken out and excluded from “organic” totals.