On Wednesday 7 May 2025 at 13:09 UTC, a carpet-bombing UDP flood targeted a crypto exchange customer in the Nordics. The attack peaked at 146.4 Gbps and lasted 17 minutes. Traffic originated from 3270 autonomous systems in 37 countries, predominantly residential proxy networks.
| Vector | carpet-bombing UDP flood |
| Peak | 146.4 Gbps |
| Duration | 17 min |
| Time to mitigation | 0.103 s |
| Attack traffic reaching origin | 0.074% |
| Legitimate traffic challenged | 0.50% |
Timeline
The attack was preceded by no stated motive. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 36 points of presence.
What the customer saw
The customer’s status page stayed green throughout; they learned about the attack from our notification.
Recommendations
- Enable log streaming to your SIEM for faster correlation.
- Keep origin IPs out of public DNS history.
- Lower challenge thresholds on authentication endpoints during high-risk events.
We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.
Great to hear, thanks for sharing your experience.
How do you avoid challenging uptime monitors and partners?
Any plans to support per-tenant limits keyed on a JWT claim?
Great to hear, thanks for sharing your experience.
Do you publish the edge IP ranges in a machine-readable format?
Do you publish the edge IP ranges in a machine-readable format?