Today in DeAI: a year-long scan counted 152,137 exposed Ollama servers, enterprise customers are revolting over AI data retention, encrypted reasoning traces leaked real secrets, and Venice AI moved toward verifiable private inference.
Year-long scan counts 152,137 exposed Ollama endpoints
Nankai University researchers probed the public internet daily for a year and found 152,137 IPs serving Ollama's unauthenticated port-11434 API, with only 0.43% to 2.90% of vulnerable hosts patching in place. Why it matters: self-hosting only buys privacy if the endpoint isn't answering the whole internet — bind to localhost and firewall the port. (arXiv) — our coverage
AI labs face an enterprise data-trust revolt
The Decoder reports that OpenAI and Anthropic's training and retention assurances are no longer believed in boardrooms: Anthropic's 30-day retention of Fable usage logs drove Palantir, Nvidia, and Booz Allen Hamilton to pull back sensitive work, and Anthropic has promised Enterprise Frontier Safeguards in response. Why it matters: retention terms are now procurement decisions, and every provider promise cited here is a claim awaiting its audit. (The Decoder)
Encrypted reasoning traces leaked PII and API keys
A Cloud Security Alliance note on research from ELLIS Tübingen, MPI, Snyk, and MATS shows encrypted chain-of-thought blocks from major providers could be replayed through weaker sibling models: 315,320 blocks reconstructed from 6,708 public agent transcripts yielded 367 PII artifacts and 182 credentials, much of it present only in the hidden reasoning. Why it matters: never publish agent traces, and treat provider mitigations — reportedly deployed as of August 2026 — as claims until re-tested. (CSA)
Venice AI adds E2EE and TEE inference modes on Phala infrastructure
Phala says its decentralized confidential-computing network now powers End-to-End Encrypted and TEE inference modes for Venice AI, moving Venice from policy-based privacy to hardware-isolated, verifiable handling. Why it matters: if the attestation story checks out, this is the template for provable private inference — but today it is a vendor claim on an undated blog post, so demand the attestation receipts. (Phala)
Watching tomorrow
Whether the Salesforce–Nvidia reasoning model ships open weights under a usable license — and whether Ollama or the major clouds respond to the exposure scan with safer defaults.
Sources
- Ollama in the Wild: A Longitudinal Measurement of Exposed Ollama LLM Endpoints at Internet Scale — arXiv (Nankai University, ACM IMC '26)
- AI labs have a data trust problem that their policies haven't solved — The Decoder
- Encrypted Reasoning Traces Let Attackers Steal Hidden Chain-of-Thought — Cloud Security Alliance
- Phala Partners with Venice AI to Deliver Verifiably Private AI — Phala
About DeAI
DeAI is an independent publication covering open-weight AI models, private inference, and decentralized infrastructure — the tools for running AI you actually control. We test providers on price, privacy, and refusal behavior and publish the numbers, not the vibes. DeAI is powered by Morpheus (mor.org), a decentralized inference marketplace, and covers it on the same terms as every other provider.
Powered by Morpheus and StrandCMS
Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider — we rank it wherever the data lands. StrandCMS is the open-source, agent-first framework this site is built on.
