Ollama Drama: Investigating the Prevalence of Ollama Open Instances with Censys
ID: e8b1d808-a92b-5cd5-8d89-67e70298901d
STIX ID: report--e8b1d808-a92b-5cd5-8d89-67e70298901d
Feed Name: Censys Blog
Date Published: 2025-09-24
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
Censys researchers performed an Internet-wide analysis of Ollama LLM deployments and found approximately 10.6K publicly exposed instances (after filtering suspected honeypots), with ~1.5K responding to direct API prompts. The report details concentration in major cloud providers, prevalence on non-default ports, distribution of running model sizes, and examples of returned prompts, and highlights misconfiguration risks and the potential for prompt injection, data disclosure, or other misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
