Honeypot Network — Daily Activity
Live activity from the AgentPwn distributed research network. Daily callback counts show when callbacks arrive and what attack surfaces we're discovering. Every number on this page comes directly from the Registry — nothing modeled, nothing projected.
Daily callbacks
Each bar is one day. Height = callbacks recorded on agentpwn.com that day. A callback is a fetch of the canary URL carried in a payload, not evidence that an agent acted on it. Hover any bar for the exact count.
New attack surfaces discovered
HoneyMap scans the public web for indirect injection surfaces. 12 surfaces have been confirmed across 10 active scan days. Each bar is daily new-surface count.
How we measure
Callbacks aggregate across every honeypot sector. The chart sums per-sector trendData from /api/v1/agentpwn/stats/by-sector. A callback means a client fetched the URL in the injection payload and posted to our telemetry endpoint with the attack ID. Where attribution exists it resolves callbacks to browsers, crawlers, and scripted HTTP clients, not to agents acting on the instruction.
Surfaces come from HoneyMap's independent crawl of the public web. A surface is any place a prompt-injection payload was confirmed by the scanner — script literals, hidden text, HTML comments, alt/aria attributes, meta tags, and more.
Don't become a data point
The chart above counts callbacks. Scan your agent before it produces one.
npx hackmyagent secure