Comment by davb
2 days ago
Coincidentally (?) we’ve seen a huge uptick in failed login attempts to our MFA-protected admin accounts on our self-hosted Gitlab CE instance today. They’re coming from thousands of IPs across hundreds of networks (VPS providers and, apparently, residential proxies).
There was a relative lull in GitHub bot activity the last few weeks, but they seem to be back today. I assume the promo token flood gates opened for the new models.
I dont think bots need bonus/trials. There are lots and lots of ways to get free, or virtually free tokens. Hell half the vibe coded AI chrome extensions send store their openrouter keys client side.
It's probably related to the issue published by aikidolabs where leaked per-user gitlab issued emails were being used as a sort of credential.
https://www.aikido.dev/blog/gitlab-email-push-to-main