Unsecured AI Ollama Hosts Found Exposed Online

Massive exposure of 175,000 Ollama AI hosts with tool-calling capabilities exploited by Operation Bizarre Bazaar.

  • Security researchers identified approximately 175,000 publicly accessible Ollama AI hosts across 130 countries, most with high-risk capabilities.
  • Nearly half of these exposed systems support tool-calling, enabling them to execute code and interact with external systems without proper authentication.
  • An active criminal operation, dubbed Operation Bizarre Bazaar, is already scanning for and selling access to these vulnerable AI endpoints.

A new joint investigation by SentinelOne SENTINELLABS and Censys has uncovered a massive, unmanaged global network of exposed Ollama AI infrastructure, creating a serious security blind spot for organizations. This sprawling network of 175,000 unique hosts operates outside standard platform guardrails, with the largest concentration located in China.
Consequently, the publicly accessible nature of these systems poses new security concerns requiring novel defensive approaches. Nearly 50% of observed hosts are configured with tool-calling capabilities, meaning they can execute code and access APIs. Researchers Gabriel Bernadett-Shapiro and Silas Cutler added that this “fundamentally alter[s] the threat model.”
Meanwhile, the risk of infrastructure abuse, termed LLMjacking, has moved from theory to practice. A separate report from Pillar Security this week details an active campaign dubbed Operation Bizarre Bazaar, where attackers scan for and sell access to these endpoints. This operation has been traced to a threat actor named Hecker.
The decentralized and often residential nature of this infrastructure complicates traditional governance and monitoring. Therefore, defenders must treat externally accessible LLMs with the same stringent controls as other critical infrastructure.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

US Debt Hits $578B Quarter, BRICS Sell-Off Sparks Alarm

The U.S. Department of the Treasury projects borrowing $578 billion in Q1 2026, a...

Crypto trader loses $50M in swap, gets only 324 tokens

A crypto trader executing a $50 million swap for AAVE tokens on Cow Swap...

Struggling Bitcoin Miners May Pivot to AI: Wintermute

Diminishing returns from Bitcoin mining are forcing miners to explore new revenue avenues, such...

Global Botnet SocksEscort Dismantled by FBI, Europol

An international law enforcement operation called Operation Lightning has dismantled the SocksEscort proxy service,...

US Gas Prices Hit 2-Year High as Iran Conflict Shuts Key Oil Route

The U.S. national average gas price has surged to $3.60 per gallon, a 20%...

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...