[object Object]

← back to Domain Sniper

honeypot: 3.87h full 50-bait check — 0/50 across all 5 buckets

7b71df770663e471a7f360f858449ddfca0b44b0 · 2026-05-12 17:30:41 -0700 · steve

Definitive negative result at the 4h mark. Pure-random CVCVC names like
kuwavi / tahoz / fobahu produced ZERO snipes despite the 2026-05-12
lure phase. All 50 bait names still available per the DoH-only check.

This contradicts the naive 'leak query => snipe within minutes' model
seen for callr.app / callr.co / butlr.app. Hypothesis: aggregators
filter leak streams for desirability (English-likeness, brand-adjacency,
prior-search signal) before paying registry fees. Random gibberish isn't
worth the cost.

Cumulative spot-check curve now 0/110 DoH checks across 11 datapoints.
Next iteration should use English-pronounceable / brand-adjacent baits.

Files touched

Diff

commit 7b71df770663e471a7f360f858449ddfca0b44b0
Author: steve <steve@designerwallcoverings.com>
Date:   Tue May 12 17:30:41 2026 -0700

    honeypot: 3.87h full 50-bait check — 0/50 across all 5 buckets
    
    Definitive negative result at the 4h mark. Pure-random CVCVC names like
    kuwavi / tahoz / fobahu produced ZERO snipes despite the 2026-05-12
    lure phase. All 50 bait names still available per the DoH-only check.
    
    This contradicts the naive 'leak query => snipe within minutes' model
    seen for callr.app / callr.co / butlr.app. Hypothesis: aggregators
    filter leak streams for desirability (English-likeness, brand-adjacency,
    prior-search signal) before paying registry fees. Random gibberish isn't
    worth the cost.
    
    Cumulative spot-check curve now 0/110 DoH checks across 11 datapoints.
    Next iteration should use English-pronounceable / brand-adjacent baits.
---
 README.md | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/README.md b/README.md
index 98990d0..2085939 100644
--- a/README.md
+++ b/README.md
@@ -55,11 +55,13 @@ Spot-checks via DoH at increasing intervals to find where the snipe window close
 | ~3.2h  | A/B/C/D/E (2 ea, slice 2-3) | 0 / 10 |
 | ~3.24h | A/B/C/D/E (2 ea, slice 4-5) | 0 / 10 — **30 of 50 baits checked, all 0** |
 | ~3.49h | A/B/C/D/E (2 ea, slice 0-1 re-check) | 0 / 10 — no late snipes between 3.08h and 3.49h |
-| ~4h    | full 50-bait sweep (queued)  | — |
+| ~3.87h | full 50-bait sweep | **0 / 50** (A 0/10, B 0/10, C 0/10, D 0/10, E 0/10) |
 | ~6h    | _pending_        | — |
 | ~24h   | full batch       | — |
 | ~48h   | full batch (final) | — |
 
+**Interpretation of the 3.87h flat result** — pure-random CVCVC bait names (`kuwavi`, `tahoz`, `fobahu`) across Verisign/Google-.app/nic.co/GoDaddy/control channels produced ZERO snipes despite deliberate leaks. The original callr.app / callr.co / butlr.app snipes hit pronounceable English-flavored names. Hypothesis: aggregators filter leak streams for desirability (English-likeness, brand-adjacency, prior-search signal) before paying registry fees. Next experimental iteration should use English-pronounceable / brand-adjacent baits to confirm.
+
 ## Known issues — public CT-log infrastructure is fragile
 
 State of the world for **free** real-time CT-log access, as of 2026-05-12 ~23:05 UTC:

← 549f3fb brand-typo-watcher: suppress known-noise patterns (Let's Enc  ·  back to Domain Sniper  ·  honeypot-v2: scaffold with desirability-shaped baits (lure g 47a41bc →