Honeypot Network — Daily Activity

Live activity from the AgentPwn distributed research network. Daily callback counts reveal when agents are most active and what attack surfaces we're discovering. Every number on this page comes directly from the Registry — nothing modeled, nothing projected.

Total interactions
190.3K
Callbacks (30d)
1.4K
Surfaces tracked
404
Domains observed
322

Daily callbacks

Each bar is one day. Height = agents that fell for an injection on agentpwn.com that day. Hover any bar for the exact count.

Apr 30May 15May 30

New attack surfaces discovered

HoneyMap scans the public web for indirect injection surfaces. 89 surfaces have been confirmed across 25 active scan days. Each bar is daily new-surface count.

May 1May 16May 30

How we measure

Callbacks aggregate across every honeypot sector. The chart sums per-sector trendData from /api/v1/agentpwn/stats/by-sector. A callback means the agent followed the injection payload and posted to our telemetry endpoint with the attack ID.

Surfaces come from HoneyMap's independent crawl of the public web. A surface is any place a prompt-injection payload was confirmed by the scanner — script literals, hidden text, HTML comments, alt/aria attributes, meta tags, and more.

Don't become a data point

The chart above counts agents that already fell for an injection. Scan yours before it ends up on the wrong side of the bar.

npx hackmyagent secure