
Image credit: Search Engine Journal
Global internet machine traffic is projected to exceed human-generated traffic by 1,000 times within five years, Cloudflare Chief Financial Officer Thomas Seifert said, as a researcher simultaneously uncovered mislabeled credential-scanning bots.
The prediction highlights a rapidly developing digital environment where artificial intelligence and automated systems increasingly dominate web activity, while also exposing new cybersecurity vulnerabilities from bots masquerading as legitimate AI crawlers.
Cloudflare had previously underestimated the growth of non-human traffic, expecting it to surpass human activity in 2027; however, that milestone was reached in May 2026, according to Seifert.
Separately, researcher Slobodan Manic reported that the largest “AI crawler” on his website, identified as Common Crawl (CCBot) by Cloudflare, was in fact a credential scanner.
The bot was observed searching for sensitive files such as SSH keys and configuration files, rather than typical website content.
Manic noted that the credential scanner specifically requested paths like /.ssh/known_hosts, /phpinfo.php, and /.env.production.
Cloudflare’s security logs did not record this credential scanning activity as a security event because it did not trigger any blocking rules, making it effectively invisible to standard security monitoring, Manic said.
The discovery shows a gap in how some automated traffic is categorized and monitored, potentially allowing malicious bots to operate undetected under the guise of legitimate services like Common Crawl, ChatGPT, Google, ClaudeBot, or PetalBot.
New paths, including /.mcp.json and /.continue/config.json, have recently been added to standard secret-scanning wordlists, according to Manic. These paths are associated with agent tooling configuration and could potentially contain API keys or other sensitive information.
The dual developments point to an urgent need for enhanced detection mechanisms to differentiate between legitimate AI-driven web activity and malicious automated credential harvesting attempts.
Source: Search Engine Journal
Written by
Palumbo Angela
Angela Palumbo, Senior Editor at Rabbit Rank since 2023, holds a bachelor's in communications. She focuses on fact-checking and simplifying complex topics while also leading strategy for the news department.
Keep reading
Related Articles

Global Brands Adopt AEO for AI Search Visibility, Shifting Focus
Brands are developing Answer Engine Optimization (AEO) strategies to ensure visibility and drive conversions w...

Ahrefs Webinar to Guide Marketers on Securing AI Search Citations
Ahrefs will host a webinar featuring Constance Tan to guide marketers on converting AI visibility data into ac...

AI Agents Expose E-commerce Checkout Flaws Amid Rapid Growth
AI agents are transforming e-commerce, but existing checkout systems struggle with machine speed. Learn key te...