
Image credit: Search Engine Journal
Global internet machine traffic is projected to exceed human-generated traffic by 1,000 times within five years, Cloudflare Chief Financial Officer Thomas Seifert said, as a researcher simultaneously uncovered mislabeled credential-scanning bots.
The prediction highlights a rapidly developing digital environment where artificial intelligence and automated systems increasingly dominate web activity, while also exposing new cybersecurity vulnerabilities from bots masquerading as legitimate AI crawlers.
Cloudflare had previously underestimated the growth of non-human traffic, expecting it to surpass human activity in 2027; however, that milestone was reached in May 2026, according to Seifert.
Separately, researcher Slobodan Manic reported that the largest “AI crawler” on his website, identified as Common Crawl (CCBot) by Cloudflare, was in fact a credential scanner.
The bot was observed searching for sensitive files such as SSH keys and configuration files, rather than typical website content.
Manic noted that the credential scanner specifically requested paths like /.ssh/known_hosts, /phpinfo.php, and /.env.production.
Cloudflare’s security logs did not record this credential scanning activity as a security event because it did not trigger any blocking rules, making it effectively invisible to standard security monitoring, Manic said.
The discovery shows a gap in how some automated traffic is categorized and monitored, potentially allowing malicious bots to operate undetected under the guise of legitimate services like Common Crawl, ChatGPT, Google, ClaudeBot, or PetalBot.
New paths, including /.mcp.json and /.continue/config.json, have recently been added to standard secret-scanning wordlists, according to Manic. These paths are associated with agent tooling configuration and could potentially contain API keys or other sensitive information.
The dual developments point to an urgent need for enhanced detection mechanisms to differentiate between legitimate AI-driven web activity and malicious automated credential harvesting attempts.
Source: Search Engine Journal
Written by
Palumbo Angela
Angela Palumbo, Senior Editor at Rabbit Rank since 2023, holds a bachelor's in communications. She focuses on fact-checking and simplifying complex topics while also leading strategy for the news department.
Keep reading
Related Articles

OpenAI says robots.txt may not apply to ChatGPT’s fetch bot
OpenAI argues robots.txt rules may not apply to ChatGPT’s fetch bot for user-initiated requests, leading to wi...

Anthropic to Watermark Claude AI Text for EU Users Under New Act
Anthropic plans Claude AI watermarking for EU AI Act compliance, sparking debate among writers and developers...

YouTube Promotes Creator Search Lift Amid Attribution Challenges
YouTube is promoting creator partnerships based on branded search lift, but a new report reveals significant a...