What 2,043 Login Attempts Told Us About Our Own Server
Last week I did something I had put off for months: I actually read the logs.
Our server is nothing special. One box, a few containers, some things we built. It does not advertise itself. It is not in anyone's directory. And still, in seven days, **595 different machines knocked on its door 2,043 times**.
That part did not surprise me. Every server on the internet gets knocked on. What surprised me was **what they asked for**.
They were not looking for a server. They were looking for a wallet.
Here are the usernames the bots tried, most frequent first:
``` admin (302) user (72) wallet (49) etherscan (49) noderpc (48) vault (43) trustvault (43) contract (42) trongrid (41) usdt (38) ```
Read that list again. After the two generic ones, everything is crypto: `wallet`, `vault`, `trustvault`, `usdt`, `trongrid`, `noderpc`, `etherscan`.
These are not people guessing. These are automated scanners with a target profile, and the profile is "a machine that might be holding keys." A few years ago the same bots were looking for `oracle`, `postgres`, `minecraft`. Now they are looking for your seed phrase.
If you run anything in this space, that is the whole lesson. You are not a random box in a rack. You are a line item in someone's scan list, filed under "might have money on it."
Where they came from, and why the map lies
We traced the top attackers:
| Country | IPs | Attempts | |---|---|---| | United Kingdom | 4 | 339 | | United States | 15 | 158 | | Germany | 6 | 62 | | France | 6 | 37 | | Russia | 8 | 24 | | Australia | 1 | 23 | | Hong Kong | 4 | 19 | | Netherlands | 3 | 16 | | Iran | 5 | 15 | | Turkey, India, South Korea, Ukraine, China | 3-4 each | ~12 each |
The UK sits at the top with 339 attempts, but that number comes from only four addresses, and three of them belong to the same hosting company in Rushden, a small town in England. Their reverse DNS names are almost charming: `dns112.personaliseplus.com`, `hosting25.tronicsat.com`.
Nobody in Rushden is attacking us. Somebody rented a machine there.
That is the honest caveat about every attack map you have ever seen: **44 out of the top 100 addresses were datacenter IPs**. These maps do not show where attackers live. They show where attackers shop.
One visitor turned out to be a scientist
One address in the top ten had a reverse DNS name of `inet-research-scan-3.mpi-inf.mpg.de`.
That is the Max Planck Institute for Informatics in Saarbrücken. They scan the whole internet for academic research, and our little box was one of billions of doorbells they rang that week. So among the burglars, one guest was a scientist taking notes.
How many got in
Zero.
Not "we stopped them." They never had a chance, because there was no lock to pick:
- **Password authentication is turned off.** Key only. This is why our logs show 2,043 invalid-user lines and zero failed-password lines. The bots could not even reach the stage where a password matters. - **Root accepts keys only.** - **fail2ban** bans repeat offenders automatically. At the time of writing: 419 addresses currently banned, 474 total.
Every successful login that week came from our own key, from our own home connection.
The boring advice that actually works
You do not need a security budget to survive this. You need three lines of configuration:
1. `PasswordAuthentication no` — this single line makes 2,043 attempts meaningless. 2. Key-based login, and keep the key off shared machines. 3. fail2ban, or anything that bans repeat offenders. Set it and forget it.
And one rule that is not about configuration: **the keys that matter should never live on a machine that faces the internet.** Not on the server that runs your website. Not on the box running your node. The bots already told us what they are shopping for. Believe them.
Why we are publishing this
We build identity and messaging tools where the user holds their own keys. The whole thesis is that the key should live with the person, not on somebody's server. This week our own logs made that argument better than our documentation does.
2,043 knocks. Zero answers. That is the goal.