Uploaded February 2026 | Updated September 2026, 3 weeks ago
On February 3, 2026, the I2P anonymity network was flooded with 700,000 hostile nodes in what became one of the most devastating Sybil attacks an anonymity network has ever experienced. The network normally operates with 15,000 to 20,000 active devices. The attackers overwhelmed it by a factor of 39 to 1.
For three consecutive years, I2P has been hit with Sybil attacks every February. The 2023 and 2024 attacks used malicious floodfill routers and remain unattributed. When the 2026 attack began, most assumed it was the same state-sponsored operation continuing its annual disruption campaign. The assumption was wrong.
The attacker was identified as the Kimwolf botnet, an IoT botnet that infected millions of devices including streaming boxes and consumer routers throughout late 2025. Kimwolf is the same operation behind the record-setting 31.4 terabit per second DDoS attack in December 2025. The operators admitted on Discord they accidentally disrupted I2P while attempting to use the network as backup command-and-control infrastructure after security researchers destroyed over 550 of their primary C2 servers.
The I2P development team responded by shipping version 2.11.0 just six days after the attack began. The release includes hybrid ML-KEM plus X25519 post-quantum encryption enabled by default, making I2P one of the first production anonymity networks to ship post-quantum cryptography to all users. Additional Sybil mitigations, SAMv3 API upgrades, and infrastructure improvements were included.
☆-----☆-----☆-----☆-----☆ CHAPTERS ☆-----☆-----☆-----☆-----☆
00:00 What is I2P?
00:58 The 700K Node Attack
01:45 History of Sybil Attacks on I2P
02:19 It Was Actually a Botnet (Kimwolf)
03:49 Why Kimwolf Targeted I2P
04:27 The Sybil Vulnerability Researchers Warned About
05:48 What a State Actor Could Do
06:34 Government Attacks on Privacy & Anonymity
08:23 I2P's Response: Version 2.11.0
09:41 Post-Quantum Crypto & Sybil Mitigations
10:31 I2P vs Tor Project Comparison
10:53 Kimwolf Is Falling Apart
11:31 The Bigger Protocol-Level Problem
12:45 Update Now & Final Thoughts
#i2p
☆-----☆-----☆-----☆-----☆ SOCIAL MEDIA ☆-----☆-----☆-----☆-----☆
🎙️ Podcast: rss.com/podcasts/darknet
🌐 Official Website: doingfedtime.com
🌐 Official Website Mirror: sambent.com
📘 Facebook: facebook.com/TheOfficialSamBent
🐦 Twitter/X: twitter.com/DoingFedTime
💼 LinkedIn: linkedin.com/in/sam-bent
📧 Email: contact@sambent.com
📱 TikTok: facebook.com/TheOfficialSamBent
📚 Amazon Author Page: amazon.com/stores/Sam-Bent/author/B0BHX5V81S
🌐 Dread (Onion Link): http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/doingfedtime
🌐 Pitch (Onion Link): http://pitchprash4aqilfr7sbmuwve3pnkpylqwxjbj2q5o4szcfeea6d27yd.onion/@doingfedtime
🐙 GitHub: github.com/DoingFedTime
👾 Reddit (User Account): reddit.com/user/reservesteel9
📽️ Rumble: rumble.com/c/SamBent
🛡️ Breach Forums (Onion Link): http://breached26tezcofqla4adzyn22notfqwcac7gpbrleg4usehljwkgqd.onion/User-SamBent
📸 Instagram: instagram.com/sambentoffical
📌 Pinterest: pinterest.com/DoingFedTime
☆-----☆-----☆-----☆-----☆ LEGAL STUFF☆-----☆-----☆-----☆-----☆
The information provided in this video is intended for educational purposes only. It is not intended to be legal or professional advice, and should not be relied upon as such.
By watching this video, you acknowledge that you understand and agree to these terms. If you disagree with these terms, do not watch this video.
On February 3, 2026, the I2P anonymity network was flooded with 700,000 hostile nodes in what became one of the most devastating Sybil attacks an anonymity network has ever experienced. The network normally operates with 15,000 to 20,000 active devices. The attackers overwhelmed it by a factor of 39 to 1.
For three consecutive years, I2P has been hit with Sybil attacks every February. The 2023 and 2024 attacks used malicious floodfill routers and remain unattributed. When the 2026 attack began, most assumed it was the same state-sponsored operation continuing its annual disruption campaign. The assumption was wrong.
The attacker was identified as the Kimwolf botnet, an IoT botnet that infected millions of devices including streaming boxes and consumer routers throughout late 2025. Kimwolf is the same operation behind the record-setting 31.4 terabit per second DDoS attack in December 2025. The operators admitted on Discord they accidentally disrupted I2P while attempting to use the network as backup command-and-control infrastructure after security researchers destroyed over 550 of their primary C2 servers.
The I2P development team responded by shipping version 2.11.0 just six days after the attack began. The release includes hybrid ML-KEM plus X25519 post-quantum encryption enabled by default, making I2P one of the first production anonymity networks to ship post-quantum cryptography to all users. Additional Sybil mitigations, SAMv3 API upgrades, and infrastructure improvements were included.
☆-----☆-----☆-----☆-----☆ CHAPTERS ☆-----☆-----☆-----☆-----☆
00:00 What is I2P?
00:58 The 700K Node Attack
01:45 History of Sybil Attacks on I2P
02:19 It Was Actually a Botnet (Kimwolf)
03:49 Why Kimwolf Targeted I2P
04:27 The Sybil Vulnerability Researchers Warned About
05:48 What a State Actor Could Do
06:34 Government Attacks on Privacy & Anonymity
08:23 I2P's Response: Version 2.11.0
09:41 Post-Quantum Crypto & Sybil Mitigations
10:31 I2P vs Tor Project Comparison
10:53 Kimwolf Is Falling Apart
11:31 The Bigger Protocol-Level Problem
12:45 Update Now & Final Thoughts
#i2p
☆-----☆-----☆-----☆-----☆ SOCIAL MEDIA ☆-----☆-----☆-----☆-----☆
🎙️ Podcast: rss.com/podcasts/darknet
🌐 Official Website: doingfedtime.com
🌐 Official Website Mirror: sambent.com
📘 Facebook: facebook.com/TheOfficialSamBent
🐦 Twitter/X: twitter.com/DoingFedTime
💼 LinkedIn: linkedin.com/in/sam-bent
📧 Email: contact@sambent.com
📱 TikTok: facebook.com/TheOfficialSamBent
📚 Amazon Author Page: amazon.com/stores/Sam-Bent/author/B0BHX5V81S
🌐 Dread (Onion Link): http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/d/doingfedtime
🌐 Pitch (Onion Link): http://pitchprash4aqilfr7sbmuwve3pnkpylqwxjbj2q5o4szcfeea6d27yd.onion/@doingfedtime
🐙 GitHub: github.com/DoingFedTime
👾 Reddit (User Account): reddit.com/user/reservesteel9
📽️ Rumble: rumble.com/c/SamBent
🛡️ Breach Forums (Onion Link): http://breached26tezcofqla4adzyn22notfqwcac7gpbrleg4usehljwkgqd.onion/User-SamBent
📸 Instagram: instagram.com/sambentoffical
📌 Pinterest: pinterest.com/DoingFedTime
☆-----☆-----☆-----☆-----☆ LEGAL STUFF☆-----☆-----☆-----☆-----☆
The information provided in this video is intended for educational purposes only. It is not intended to be legal or professional advice, and should not be relied upon as such.
By watching this video, you acknowledge that you understand and agree to these terms. If you disagree with these terms, do not watch this video.










