Unsecured AI Ollama Hosts Found Exposed Online

Massive exposure of 175,000 Ollama AI hosts with tool-calling capabilities exploited by Operation Bizarre Bazaar.

  • Security researchers identified approximately 175,000 publicly accessible Ollama AI hosts across 130 countries, most with high-risk capabilities.
  • Nearly half of these exposed systems support tool-calling, enabling them to execute code and interact with external systems without proper authentication.
  • An active criminal operation, dubbed Operation Bizarre Bazaar, is already scanning for and selling access to these vulnerable AI endpoints.

A new joint investigation by SentinelOne SENTINELLABS and Censys has uncovered a massive, unmanaged global network of exposed Ollama AI infrastructure, creating a serious security blind spot for organizations. This sprawling network of 175,000 unique hosts operates outside standard platform guardrails, with the largest concentration located in China.
Consequently, the publicly accessible nature of these systems poses new security concerns requiring novel defensive approaches. Nearly 50% of observed hosts are configured with tool-calling capabilities, meaning they can execute code and access APIs. Researchers Gabriel Bernadett-Shapiro and Silas Cutler added that this “fundamentally alter[s] the threat model.”
Meanwhile, the risk of infrastructure abuse, termed LLMjacking, has moved from theory to practice. A separate report from Pillar Security this week details an active campaign dubbed Operation Bizarre Bazaar, where attackers scan for and sell access to these endpoints. This operation has been traced to a threat actor named Hecker.
The decentralized and often residential nature of this infrastructure complicates traditional governance and monitoring. Therefore, defenders must treat externally accessible LLMs with the same stringent controls as other critical infrastructure.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Aave Dev Team BGD Labs Exits Amid DAO Conflict

BGD Labs, the key developer of Aave v3, is ending its service contract with...

Aave’s BGD Labs Ends 4-Year DAO Partnership

BGD Labs, a primary developer for the Aave protocol, announced it will end its...

AI Tool Cline CLI Hijacked in Supply Chain Attack

The AI-powered Cline CLI npm package was compromised, leading to an unauthorized update that...

Can SHIB Recover? Experts Weigh In on Shiba Inu’s Comeback Odds

In 2021, Shiba Inu delivered a staggering 85,000,000% return and briefly surpassed Dogecoin in...

DPRK Crypto Theft Accelerates Post-Bybit, Shifts to Fake Projects

DPRK-led crypto theft has escalated, stealing a record $2 billion in 2025 and accelerating...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!