https://www.sambent.com/a-botnet-accidentally-destroyed-i2p-the-full-story/ Sam Bent * Home * Contact Me * Briefings * Intercepts Sign in Subscribe botnet A Botnet Accidentally Destroyed I2P (The Full Story) Sam Sam 21 Feb 2026 -- 1 min read A Botnet Accidentally Destroyed I2P (The Full Story) On February 3, 2026, the I2P anonymity network was flooded with 700,000 hostile nodes in what became one of the most devastating Sybil attacks an anonymity network has ever experienced. The network normally operates with 15,000 to 20,000 active devices. The attackers overwhelmed it by a factor of 39 to 1. For three consecutive years, I2P has been hit with Sybil attacks every February. The 2023 and 2024 attacks used malicious floodfill routers and remain unattributed. When the 2026 attack began, most assumed it was the same state-sponsored operation continuing its annual disruption campaign. The assumption was wrong. The attacker was identified as the Kimwolf botnet, an IoT botnet that infected millions of devices including streaming boxes and consumer routers throughout late 2025. Kimwolf is the same operation behind the record-setting 31.4 terabit per second DDoS attack in December 2025. The operators admitted on Discord they accidentally disrupted I2P while attempting to use the network as backup command-and-control infrastructure after security researchers destroyed over 550 of their primary C2 servers. The I2P development team responded by shipping version 2.11.0 just six days after the attack began. The release includes hybrid ML-KEM plus X25519 post-quantum encryption enabled by default, making I2P one of the first production anonymity networks to ship post-quantum cryptography to all users. Additional Sybil mitigations, SAMv3 API upgrades, and infrastructure improvements were included. Read more Tor Browser 15.0.6 Ships New Circuit Encryption Tor Browser 15.0.6 Ships New Circuit Encryption Tor Browser 15.0.6 ships with Counter Galois Onion circuit encryption that eliminates tagging attacks, plus a heap buffer overflow patch from Firefox ESR 140.7.1. By Sam 17 Feb 2026 Whonix 18.1.4.2 Patches a VM Fingerprinting Flaw Whonix 18.1.4.2 Patches a VM Fingerprinting Flaw Whonix 18.1.4.2 disables VirtualBox dynamic resolution by default after developers discovered the auto-resize feature creates unique fingerprints that persist across reboots. By Sam 15 Feb 2026 FBI Took 20 Years to Kill a Router Botnet FBI Took 20 Years to Kill a Router Botnet A criminal proxy service openly bragged "Working since 2004!" on its homepage while the FBI apparently had other priorities for two decades. By Sam 13 Feb 2026 I2P 2.11.0 Ships Post-Quantum Crypto After Botnet Siege I2P 2.11.0 Ships Post-Quantum Crypto After Botnet Siege A botnet that broke DDoS records at 31.4 terabits per second accidentally crippled I2P's anonymity network while trying to use it as a backup command infrastructure, and the developers responded with post-quantum cryptography enabled by default. By Sam 13 Feb 2026 Sam Bent * Sign up Powered by Ghost Sam Bent Darknet & Darkweb News, OpSec, OSINT and More [ ] Subscribe Coins by Cryptorank