
SondeHub: how a joke domain purchase became part of modern warfare
SondeHub started in 2018 as a joke redirect for weather-balloon trackers. Its founder now describes how its wind predictions ended up in military hands, and what that cost him.
SondeHub began in May 2018 as a joke: a domain registered to send visitors to the Habhub ballooning site with a filter for weather balloons rather than amateur ones. Eight years on, its operator writes that the service's wind predictions are used by military units, and that handling that reality became an ethical and legal problem.
From joke redirect to public infrastructure
The post on sprocketfox.io recalls how Australian balloon chasers tracked radiosondes — the transmitters on weather balloons — on Habhub, a site built for amateur balloons. When Habhub began hiding weather balloons by default, sondehub.org was registered on 12 May 2018 simply to point there with a radiosonde filter. By 2019 the project had its own APIs and backend, and unlike official software of the era it tracked radiosondes to the ground, attracting requests from government agencies. The team also built a "reverse prediction" system that runs the wind model backwards from a launched radiosonde's data to estimate its launch site.
Artillery sites, accidentally mapped
In 2021 an email described a sensitive military installation and asked that it not be marked on any map. Wind data, the author notes, also feeds artillery ranging calculations, so reverse predictions were inadvertently mapping artillery sites; the feature stayed, but launch sites are deleted on genuine requests.
One IP address
In December 2024, alerts flagged prediction traffic hammering the API. Logging traced it to a single IP on an AWS network, ruling out a suspected commercial reseller. Plotted coordinates pointed instead to a unit using SondeHub's forecasts to plan deep strikes. A relayed message described groups that "fly fixed-wing and use Sondehub to help them 'surf' the sky to target areas"; a Ukrainian-language appeal asked a deep-strike team running a Python script with an open-source wind engine to make contact, because its queries risked getting the service blocked.
Keeping the service alive
A Docker Compose file was published so anyone could run their own predictor without depending on the authors, and AWS was asked not to block or terminate the source account — the argument being that "loss of life could occur" and that request logs could reveal launch sites. AWS replied that a Lambda function had been flagged for scraping the API. The post also recounts a data request from the US "Office of the Secretary of War (Intelligence and Security)"; the team invoiced it, and the invoice was never paid.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.