logo

Ollama Drama: Investigating the Prevalence of Ollama Open Instances with Censys

ID: e8b1d808-a92b-5cd5-8d89-67e70298901d

STIX ID: report--e8b1d808-a92b-5cd5-8d89-67e70298901d

Feed Name: Censys Blog

Threat Score
50/100

Date Published: 2025-09-24

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

Censys researchers performed an Internet-wide analysis of Ollama LLM deployments and found approximately 10.6K publicly exposed instances (after filtering suspected honeypots), with ~1.5K responding to direct API prompts. The report details concentration in major cloud providers, prevalence on non-default ports, distribution of running model sizes, and examples of returned prompts, and highlights misconfiguration risks and the potential for prompt injection, data disclosure, or other misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.