← Return to rangeHYVE OVERLORD
Day 30 · Field Report · Jul 2026

One month of live fire. Zero breaches.

A real $1,000Visa gift card has sat behind Hyve Raptor for 30 days, in the open, with the public API key published. This is the honest month-in-review — every number below is a live aggregate from the range’s own database, with our commissioning tests and self-run red-team broken out separately.

29,041
Requests logged
2,087
Attacker sources
72
Countries
3,121
Genuine attacks
5,716
Defeated (all-time)
0
Breaches

The traffic, honestly

Not every request is an external attacker, and we won’t pretend otherwise. Here is where the 29,041 logged requests actually came from:

19,085
Launch-day resilience test

Synthetic load we fired on day one to prove the ingest + classify pipeline holds under a flood. Not external actors.

8,403
Organic external traffic

Real internet actors — 2,087 unique sources across 72 countries. 3,121 carried a genuine attack signature.

Audit + red team
Our own adversarial work

An independent security audit and a self-run nation-state red team, including a direct database assault with the public key. All logged, all repelled.

How they attacked

Top organic attack vectors (external actors only)
Admin / login recon
2,260
Volumetric / L7 flood
762
Bot traffic
727
WordPress takeover
525
Credential-file recon
149
SSRF
25
Scripted client
14
Config exposure
14
anomaly
3
Command injection
2

The real-world picture of a random honeypot: opportunistic recon and bots, not a targeted 0-day campaign. The exotic exploit families (Log4Shell, SQLi floods, template injection) showed up mostly in our commissioning and red-team runs — Raptor holds a signature for each regardless.

Where they came from

Top origin countries (organic)
🇺🇸 US
3,681
🇩🇪 DE
1,107
🇸🇪 SE
868
🇳🇱 NL
333
🇮🇳 IN
268
🇸🇬 SG
237
🇨🇳 CN
196
🇬🇧 GB
179
🇷🇺 RU
178
🇨🇦 CA
130
Open the live threat map →

30 days at a glance

Requests per day (red = high/critical)

The day-one spike is the resilience stress test. After commissioning, organic traffic settled to a steady ~150–400 requests/day — punctuated by the audit and red-team runs.

Severity mix

Organic events by classified threat level
critical
675
high
72
medium
89
low
2,285
info
5,282

What we shipped this month

01
Independent security audit → remediated

A 30-finding external audit of the range's own code. Every finding closed: a transactional single-winner prize path, cross-instance rate-limiting, consent-gated telemetry, single-owner admin authorization (MFA-ready), plus lint/tests/CI gates.

02
Nation-state red team → repelled

We attacked our own range: a direct database assault with the public key (RLS returned nothing), then advanced WAF-evasion, CVE chains, injection and AI-poisoning. Ejected on first contact. The vault never moved.

03
Sharper detection

New signatures for AI-attack tradecraft (prompt injection, jailbreaks, Pliny markers, glitch tokens, invisible-Unicode smuggling) and credential-file recon (.env / .git / .aws) that now ejects on first contact.

04
Intel shipped to the product

Everything the range learned was ported into HYVE Overlord and re-published, so a customer's install detects the same tradecraft the live range does.

The vault

$1,000
Sealed · live bounty

901 people have submitted a code to the vault. None matched.The code lives in a table only the server can read — even with the public key, the front end can’t reach it. That’s why 30 days in the open changed nothing.

Attempt the breach →

Figures are live aggregates from the range database, refreshed periodically. Commissioning stress-test and our own red-team traffic are broken out and excluded from “organic” totals.