If you work in security, you spend your time in things that are very obviously real: users forgetting passwords, weird processes on a box at 3 a.m., logs that won’t parse, malware that absolutely does execute when you run it in the wrong place.
Against that backdrop, “Dead Internet Theory” sounds stupid on its face. The internet is obviously still here. People are clearly still online, still breaking things, still opening phishing attachments they shouldn’t.
But if you zoom out from the tickets and look at what’s actually flowing across the wire and sitting on the public web, the theory starts to sound less like a joke and more like a distorted description of something measurable. Bot traffic really is enormous. A lot of what search engines return really is AI sludge. Social feeds really are full of content that nobody seems to have written.
The conspiracy story is wrong. The environment it’s reacting to isn’t.
This is an attempt to put some structure to that: where Dead Internet Theory came from, what it’s actually claiming, what the data says, and what that means if you treat the internet as one of your sensors for reality.
Where Dead Internet Theory came from
The phrase didn’t come from an academic paper or a policy brief. It came from a long paranoid thread on a small nostalgia forum.
In early 2021, a user calling themselves “IlluminatiPirate” posted a piece titled “Dead Internet Theory: Most of the Internet Is Fake” on a site called Agora Road’s Macintosh Café. The post stitched together older imageboard paranoia with a 2018 article from New York Magazine that had already made people uncomfortable: “How Much of the Internet Is Fake? Turns Out, a Lot of It, Actually.” That article pulled together research suggesting that a large share of traffic and engagement online was already artificial years ago.
“Dead internet” in that original post meant a few specific things. First, that sometime around 2016 the visible web shifted from mostly human activity to mostly automated traffic and generated content. Second, that search engines and social platforms quietly started boosting that synthetic layer, while genuine human conversation and small sites fell out of view. Third, that states and large companies were using this environment for information operations and opinion management, blending propaganda into a background of bots and algorithmic noise.
On its own, that’s just another long anonymous rant. What gave it traction was how familiar parts of it felt to everyone who had watched the public web get hollowed out by engagement farming and SEO.
By late 2021, The Atlantic had run an article titled “Maybe You Missed It, but the Internet ‘Died’ Five Years Ago,” which walked through Dead Internet Theory and landed on a simple point: taken literally, it’s absurd, but if you’ve noticed how strange and empty the modern web feels compared to a decade ago, you understand the mood behind it.
From there it moved into research and mainstream coverage: entries in books on conspiracy culture and disinformation, BBC explainers, think tank notes, and a steady trickle of articles that all circle the same question: how much of what we see online is actually coming from people at all.
The strong version vs. the version you can’t just wave away
Once people started taking it apart, Dead Internet Theory split into two versions.
The strong version says the “real” internet effectively ended sometime in the mid-2010s. In its place we now have a kind of simulation: most accounts are NPCs, most conversations are scripted, and some combination of governments and corporations is orchestrating this for control. In this telling, human activity is the exception, not the rule.
There’s no serious evidence for that kind of coordinated switch-flip. Researchers looking at the theory come back to the same point: as a narrative about one big secret project, it doesn’t hold up.
The weaker version keeps the pieces you can actually measure. It says that a huge share of web traffic is now automated; that AI-generated and low-value content has exploded; that search and social feeds are heavily curated by opaque ranking functions; and that this whole mix is absolutely useful for manipulation if someone decides to lean into it.
You don’t have to accept any hidden “we replaced the internet” story to see that this weaker version is describing the world you’re already working in.
Bots, and why “half the internet is bots” isn’t just a meme
Almost every serious discussion of Dead Internet Theory starts with the same observation: the amount of automated traffic on the web is huge.
Back in 2016, Imperva looked at more than sixteen billion visits across one hundred thousand domains and concluded that just over half of all traffic was bots rather than humans. That wasn’t a conspiracy blog post; it was a vendor trying to sell WAFs and doing the measurement work along the way.
In the years since, those numbers have stayed high. In its 2024 Bad Bot Report, Imperva reported that in 2023, 49.6% of overall internet traffic was automated, and that 32% of all traffic was “bad bot” traffic. Human traffic accounted for just over half of total activity.
Those reports define “bot” in a simple way: any software that is automatically sending requests over HTTP(S). Inside that bucket they draw one line that actually matters:
“Good bots” are crawlers and tools that are part of the plumbing of the web: search engine indexers like Googlebot, uptime and performance monitors, legitimate API clients.
“Bad bots” are the things everyone in security is used to seeing as background radiation: credential-stuffing tools hammering login pages, content scrapers copying pricing and articles, coupon abuse, carding scripts, fake account creation, DDoS components, and so on.
When they say a third of all traffic is “bad bot traffic,” that’s what they’re talking about. It is not literally saying “one third of the people you see online are fake humans,” but it is saying that a massive chunk of what hits a typical site is software up to no good.
By 2024–2025 you end up with a picture where, on many public-facing properties, as much or more of what crosses the wire is automation rather than people. At that point, it becomes very easy for someone to look at those numbers, mash them together with how social feeds feel these days, and conclude that the internet is full of ghosts.
AI sludge stacked on top of that
Traffic is one part of the story. The other part is what’s actually sitting on the page.
After systems like ChatGPT showed up at the end of 2022, generative models stopped being a research project and turned into a content factory. Within a year, you could see the impact in measurements of the open web.
One example: Copyleaks analyzed more than a million web pages per time period and reported a 2,848 percent increase in pages containing AI-generated content between the first quarter of 2023 and the first quarter of 2024. Before that, AI content on the open web was relatively flat.
At the same time, Google was forced to publicly admit that its search results were being overrun by pages that “feel like they were created for search engines instead of people,” and that generative AI and automated publishing were fueling a lot of that.
On social platforms, the trend looks different but comes from the same root. In 2024, Facebook feeds filled up with AI-generated religious images: surreal depictions of Jesus, deformed saints, and impossible church scenes, many of them attached to posts that collected thousands of “Amen” comments within hours. Those posts were clearly not hand-painted by hobbyists; they were mass-produced slop optimized for the engagement loop.
Researchers and journalists started calling this stuff “AI slop”: content that exists only because it’s cheap to generate and performs well in the current algorithm, not because anyone had something to say.
Add to that a newer wave of AI retrieval bots – crawlers whose entire job is to scrape sites so large language models can answer questions about them – and you get a web where a growing share of both requests and responses are machine-to-machine. Measurement firms tracking this kind of traffic have already reported double-digit percentage growth in retrieval-bot traffic in a matter of months, even as human visits to those same sites decline.
Seen from that angle, Dead Internet Theory stops looking like pure paranoia and starts looking like an exaggerated description of something you can actually measure: more bots, more AI, more synthetic activity everywhere you look.
Why you don’t need a secret “simulation” to get here
The part of Dead Internet Theory that doesn’t survive contact with the evidence is the idea of a single hidden project to “replace” the internet.
Everything above can be explained by three very public forces that have been in play for years.
Advertising systems care about impressions, click-through rates, and conversions. They do not have a field called “was this a human.” If a script loads the page and fires the pixel, the graph moves the same way as if a person did it.
Recommendation systems care about watch time, engagement metrics, and retention. They are trained to show people what keeps them on the platform, not what’s true, not what’s useful, and definitely not what came from a human rather than a model.
Generative models care about producing output that looks plausible and satisfies a broad prompt. Once those models got cheap enough to run at scale, they became a simple answer to a very old business problem: “we need more content and we don’t want to pay more writers.”
Given those incentives, you don’t need a mastermind flipping switches in a bunker. The system naturally drifts toward automation and sludge. Traffic shifts toward bots because bots are cheap. Content shifts toward AI because AI is fast. Feeds shift toward whatever keeps people scrolling, whether that’s Shrimp Jesus images or AI-generated career advice written in the same voice as everyone else’s.
Dead Internet Theory is wrong about the hidden plot, but it’s not wrong that the surface of the web now behaves like a machine that has optimized human beings almost out of the loop.
What this does to security and OSINT work
If you do security, threat hunting, or OSINT, you already live with the noisy side of this.
When you try to make sense of an incident from open sources now, “what the internet is saying” is often polluted by synthetic campaigns, SEO farms, and engagement-bait garbage. The count of posts and the apparent volume of conversation around something are not reliable indicators of how many people actually care about it. Entire narratives can be manufactured by a handful of operators with the right toolchain.
On the telemetry side, your baselines are no longer clean. When half or nearly half of your incoming traffic is automated, and a third of that is hostile automation, your logs are busy before an actual attacker even shows up. Scanners, scrapers, uptime checks, CI systems, legitimate API clients, and botnets all use the same protocols and sometimes the same cloud providers. Telling “weird but normal” apart from “weird and dangerous” gets harder every year.
There’s also a human angle that comes up in disinformation research: as people get used to the idea that everything online is botted, scripted, or generated, trust turns into another attack surface. It becomes easier to get them to ignore real warnings (“that screenshot is probably fake”) or fall for well-crafted ones (“everyone is talking about this, look at all the posts”).
You end up doing for information what you already do for binaries: checking provenance, looking for tampering, and asking whether it came from somewhere you actually recognize.
Treating the internet like a semi-trusted network
My own way of coping with this is pretty simple. I treat the open internet like I would any other semi-trusted network: it’s useful, but it doesn’t get root on my brain.
If a claim matters, I don’t stop at screenshots or threads. I go looking for first-party evidence: advisories, code, packet captures, logs, reports from people who were actually in the blast radius. If a person is central to something I care about, I try to look at their timeline rather than just their latest polished post: old work, failed projects, ugly commits, anything that suggests a human history rather than a freshly-minted persona.
And more than anything, I keep my own record of reality. Notes from incidents I’ve handled. Write-ups from labs I’ve built and broken. Runbooks, configs, mistakes. All of that lives somewhere I control, so I’m not dependent on whatever a search engine decides is page one this week.
It’s just DFIR, pointed slightly outward: don’t trust, verify; don’t accept the dashboard as ground truth if you can still get to the raw data.
Why I’m running a sealed-box stack at all
This is the same logic that pushed me toward a sealed-box AI stack and a real home lab instead of betting everything on cloud tools and public models.
If the public side of the internet is tilting toward synthetic by default, I want at least one environment where the signals are clean. That means models that run on hardware I own, with logs I can actually look at. It means context that comes from my own notes, tickets, lab output, and documents—not whatever a model ingested from AI-slop SEO sites three months ago. It means having the ability to replay and verify what the system did, instead of trusting an opaque “we may use your data to improve our service” line in somebody else’s ToS.
The same goes for the lab: Active Directory, Wazuh, EDR, malware detonation networks, and all the other pieces. They’re not just there because it’s fun to tinker. They give me a known-good frame of reference. If I want to understand how something behaves, I can recreate it in a network I understand and watch it, instead of trying to reverse-engineer it from screenshots and blog posts that might themselves be AI-authored.
Most people won’t go as far as “sealed-box bunker in the corner of the living room,” and they don’t have to. But if you work in this field, some kind of personal, trusted stack with its own telemetry is going to be table stakes.
So, is the internet dead?
Not in the way the original theory claims. There is no sign that the “real” internet shut off and a fake one came online in its place.
But if by “internet” you mean the default surface—what search engines show on page one, what your social feeds push at you when you aren’t looking for anything in particular—that layer is in rough shape. A lot of the traffic hitting it is bots. A lot of the content floating on top is AI-generated filler. A lot of the engagement is scripted.
Underneath that, people are still very much alive. They’re just less visible: small sites, weird repos, long-tail blogs, DMs and group chats, niche forums, places where the algorithms aren’t doing as much of the shaping.
Dead Internet Theory, as a conspiracy, is the wrong story. As a label for an environment where bots, sludge, and engagement code have taken over most of the visible surface, it’s a useful warning.
If you work in security, it’s not your job to fix the whole web. But it is your job to be honest about what you can and can’t trust. In a landscape where large parts of the traffic and content are synthetic by default, “proof of life” stops being a metaphor and turns into a skill: your own stack, your own logs, and your own record of what actually happened.
