Live leaderboard · poisoned credentials
Bots ask our sites for their secrets all day. Each one gets a fake .env in which every credential is unique, like a 409A with a different number for every reader. When a credential comes back, we know who scraped it, who used it, and how fast.
requests for our secrets
The fastest thief
Each row is one unique fake credential, followed from the scan that took it to every attempt to use it.
Where the scanners' servers are rented, not who runs them. And how much of their haul came back.
Networks that tried a poisoned credential. Often not the one that scraped it.
We see a credential used when it points back at our own sites. The OpenAI, Anthropic and AWS keys come with a base URL that sends SDKs to us. Stripe, GitHub and SendGrid keys get tested at those companies, out of our sight.
The last 30 days. Hover a column for its value.
The most recent times a poisoned credential came back.
Everyone running Bait into this leaderboard. Sites stay private.
What the scanners asked for.