usual.BaitLoading

Live leaderboard · poisoned credentials

We poison the .env scanners.

Bots ask our sites for their secrets all day. Each one gets a fake .env in which every credential is unique, like a 409A with a different number for every reader. When a credential comes back, we know who scraped it, who used it, and how fast.

requests for our secrets

The fastest thief

Most wanted credentials

Each row is one unique fake credential, followed from the scan that took it to every attempt to use it.

Who scrapes

Where the scanners' servers are rented, not who runs them. And how much of their haul came back.

Who comes back

Networks that tried a poisoned credential. Often not the one that scraped it.

What they try

We see a credential used when it points back at our own sites. The OpenAI, Anthropic and AWS keys come with a base URL that sends SDKs to us. Stripe, GitHub and SendGrid keys get tested at those companies, out of our sight.

Over time

The last 30 days. Hover a column for its value.

Latest uses

The most recent times a poisoned credential came back.

Members

Everyone running Bait into this leaderboard. Sites stay private.

Most requested files

What the scanners asked for.