One month of live fire. Zero breaches.
A real $1,000Visa gift card has sat behind Hyve Raptor for 30 days, in the open, with the public API key published. This is the honest month-in-review — every number below is a live aggregate from the range’s own database, with our commissioning tests and self-run red-team broken out separately.
The traffic, honestly
Not every request is an external attacker, and we won’t pretend otherwise. Here is where the 29,041 logged requests actually came from:
Synthetic load we fired on day one to prove the ingest + classify pipeline holds under a flood. Not external actors.
Real internet actors — 2,087 unique sources across 72 countries. 3,121 carried a genuine attack signature.
An independent security audit and a self-run nation-state red team, including a direct database assault with the public key. All logged, all repelled.
How they attacked
The real-world picture of a random honeypot: opportunistic recon and bots, not a targeted 0-day campaign. The exotic exploit families (Log4Shell, SQLi floods, template injection) showed up mostly in our commissioning and red-team runs — Raptor holds a signature for each regardless.
Where they came from
30 days at a glance
The day-one spike is the resilience stress test. After commissioning, organic traffic settled to a steady ~150–400 requests/day — punctuated by the audit and red-team runs.
Severity mix
What we shipped this month
A 30-finding external audit of the range's own code. Every finding closed: a transactional single-winner prize path, cross-instance rate-limiting, consent-gated telemetry, single-owner admin authorization (MFA-ready), plus lint/tests/CI gates.
We attacked our own range: a direct database assault with the public key (RLS returned nothing), then advanced WAF-evasion, CVE chains, injection and AI-poisoning. Ejected on first contact. The vault never moved.
New signatures for AI-attack tradecraft (prompt injection, jailbreaks, Pliny markers, glitch tokens, invisible-Unicode smuggling) and credential-file recon (.env / .git / .aws) that now ejects on first contact.
Everything the range learned was ported into HYVE Overlord and re-published, so a customer's install detects the same tradecraft the live range does.
The vault
901 people have submitted a code to the vault. None matched.The code lives in a table only the server can read — even with the public key, the front end can’t reach it. That’s why 30 days in the open changed nothing.
Figures are live aggregates from the range database, refreshed periodically. Commissioning stress-test and our own red-team traffic are broken out and excluded from “organic” totals.