SondeHub: a joke balloon tracker caught up in war and the military

In 2017, the person who runs SondeHub was introduced to weather balloon hunting, tracking the radiosonde transmitters that ride weather balloons, by a collaborator named Mark VK5QI. At the time only Melbourne and Adelaide radiosondes were tracked, on a site called Habhub, which had been built for amateur balloons rather than official meteorological ones. As more radiosondes appeared on Habhub, its admins added a default filter that hid weather balloons, leaving a URL parameter to turn the filter off. On 12 May 2018, the operator registered sondehub.org for a single purpose: to redirect to Habhub with that filter disabled. By their own account, it was "more of a joke than a decision to run a radiosonde tracking service."
Habhub could not handle the traffic that followed. By July, SondeHub began proxying radiosonde ingestion data through its own OpenSearch cluster, mainly so the operator could experiment with Amazon Web Services tools. By 2019, Habhub's servers, and those of a similar site, aprs.fi, were struggling, pushing SondeHub to plan its own APIs and frontend. Government agencies started reaching out too: one request concerned an insurance claim after a radiosonde reportedly hit a horse and caused it to bolt through a fence, something SondeHub's system could help with because, unlike the official tools of the time, it tracked radiosondes all the way to the ground. That same year, the team noticed a sudden drop in radiosonde launches. They first suspected their own software, but traced the cause to equipment problems at radiosonde maker Vaisala around the GPS rollover date; SondeHub's own software handled the rollover without issue.
Through 2020 and 2021, SondeHub built backward-compatible APIs so the Habhub frontend could run on SondeHub's own backend, began providing open access to its data via S3, and launched its own flight predictor. With that predictor running, Mark VK5QI built what the team calls "reverse predictions": working the wind model backward from an already-landed radiosonde to estimate where it had launched. It worked well enough to identify a number of poorly documented launch sites. In 2021, SondeHub received its first email from the military, describing a "sensitive... military installation" and asking that it not be marked explicitly on any public map. That request made the operator realize wind data is not only used to forecast weather: it is also used to calculate artillery ranging, meaning SondeHub's reverse predictions had been inadvertently mapping out artillery sites. The team decided to keep running reverse predictions, but to delete specific launch site data on legitimate request; the same reverse prediction system has also flagged a number of military vessels at sea.
SondeHub kept adding features such as websocket and MQTT live feeds, and eventually removed Habhub from its pipeline entirely. Grant funding from ARDC let the team stand up a dedicated amateur ballooning version of the service, and when Habhub finally shut down for lack of maintenance, SondeHub absorbed what it could. The 2023 "China spy balloon" incident brought a surge of visitors that the site's architecture handled without much trouble. Then, on 11 February 2023, the US allegedly used an AIM-9X Sidewinder missile, priced at $439,000 in the operator's own account, to shoot down an amateur radio balloon. The Washington Post linked to SondeHub that morning, and the site absorbed the resulting traffic spike. Since then, the operator says, SondeHub has fielded a steady stream of support requests from .mil and .gov email addresses, as well as from the aviation industry and air traffic control.
In December 2024, usage alarms started firing again, this time for SondeHub's prediction endpoint, recurring roughly every week. Logging traced the heavy load to a single IP address. The operator first suspected, then ruled out, a private company quietly using SondeHub's backend to generate its own predictions, after emailing the company directly. Plotting the flagged requests, using data the post says was deliberately reduced in precision, drawn from an old and partial dataset, and held back from publication until, in the operator's words, "balloon warfare" was more widely known, pointed toward a connection with Russia's 2022 invasion of Ukraine, a war the post discusses with open hostility toward Russia. Worried about the ethical and legal implications, and suspecting the API was being misused, the operator eventually received messages through an unnamed contact. One read: "We work with mHAB's as you know, but some other groups likely fly fixed-wing and use Sondehub to help them 'surf' the sky to target areas." The same contact said they had also sent a Ukrainian-language message to several military chat groups, looking for whoever was running "a python script with some open source wind forecasting engine" so the heavy use could stop before triggering a block. SondeHub's account does not identify which country, organization or individual was actually generating the traffic. In response, the operator quickly published a Docker Compose file so that anyone could run a predictor of their own, independent of SondeHub's infrastructure.
Because the source IP for the anomalous traffic belonged to Amazon Web Services, the operator contacted AWS support directly, careful to stress that the account should not be blocked or shut off. The message read: "It is incredibly important that the http request data is not distributed. It is also important that the source AWS account is not blocked, rate limited or terminated - loss of life could occur." AWS in turn contacted its own customer, whose Lambda function had been flagged for potentially scraping SondeHub's API, and told that customer to get in touch with SondeHub directly. The two sides then exchanged emails, and SondeHub provided documentation on how to run its predictor locally instead of hitting the live API.
In 2025, the US "Office of the Secretary of War (Intelligence and Security)" requested radiosonde data from SondeHub. The operator says SondeHub usually provides data free when there is a clear community benefit, but decided the Department of War should pay, since none was expected here. Despite personal reluctance to help the US military at all, the operator reasoned that the underlying data is public anyway, so declining would only mean someone else supplied it, and SondeHub might as well raise funds for its own infrastructure instead. An invoice was sent. It was never paid, and the operator says they still do not know what the office wanted the data for. Separately, the National Transportation Safety Board (NTSB) contacted SondeHub in September 2025 over a possible collision between an aircraft and a weather balloon that had been reported via ACARS, at one point asking whether SondeHub had data on any balloons over Utah between 1200 and 1300 UTC on 16 October 2025. None of the balloons SondeHub tracks matched, but the team identified a Windborne balloon in the area; Windborne later confirmed it as the likely cause and said it had made changes to its systems to prevent a repeat.
SondeHub has fielded other unusual requests too. An airport operations supervisor once asked the operator to help coordinate around meteorological weather balloons that pilots wanted to avoid; SondeHub had to explain that those balloons are normally scheduled but not centrally controlled, and that it holds no registration or contact details for their launches, which the operator guesses, by their own admission not as a lawyer, probably fall under Part 101.D of FAA regulations. In one case, someone recovering a fallen radiosonde from a property crashed into a building on the way out and left without a note; the property owner turned to SondeHub for help identifying them. The team also tracks patterns of GPS jamming and spoofing, alongside sites such as gpsjam.org, which the operator speculates may be intended either to make jammed targets easier to identify or to crash a vehicle in a specific way. Job titles collected from correspondents over the years range from a Naval Air Warfare Center aircraft division program to a National Weather Service meteorologist and, in one case, Jennifer Billock, a freelance writer who described their own title as "Certified Tea Specialist, Cheese Fortune Teller" and had written an article about weather balloons for STNDRDS.
Key facts
- sondehub.org was registered on 12 May 2018 purely as a joke, a URL redirect to the existing amateur balloon site Habhub, before it grew into a service with its own APIs, predictor and open S3 data.
- SondeHub's "reverse predictions" system, which works backward from a landed radiosonde's flight data to estimate its launch site, has inadvertently mapped out artillery ranging sites and flagged military vessels at sea, since the same wind data used for weather forecasts is also used to calculate artillery ranging.
- After the US allegedly used an AIM-9X Sidewinder missile, priced at $439,000 in the operator's own account, to shoot down an amateur radio balloon on 11 February 2023, a Washington Post link sent traffic to SondeHub, and the site began fielding a steady stream of requests from .mil and .gov addresses.
- Starting in December 2024, SondeHub saw recurring heavy load on its prediction API from a single IP address; an unnamed contact later told the operator that other groups were suspected of using the tool to help target strike areas, and said they had messaged Ukrainian-language military chat groups trying to identify the heavy users.
- In 2025, the US "Office of the Secretary of War (Intelligence and Security)" requested radiosonde data and was invoiced for it since no community benefit was expected, but the invoice went unpaid; separately, the NTSB's 2025 outreach about a possible collision between an aircraft and a weather balloon led SondeHub to flag a Windborne balloon that the company later confirmed as the likely cause.
Why it matters
SondeHub is a case study in how quickly small, well-built infrastructure can outgrow its original joke and become load-bearing for people its operator never intended to serve. A domain that existed only as a redirect became a tool relied on, or worried about, by intelligence and defense officials, air-traffic controllers, an air-safety investigator, and, per an anonymous tip the operator could not fully verify, parties connected to a live war. The same wind-prediction math that helps a hobbyist find a fallen radiosonde also underlies artillery ranging, so a side project's technical choices, not its builders' intentions, ended up deciding how consequential it became. That gap, between what a tool is built to do and what its outputs turn out to be useful for, runs through the horse-insurance claim, the accidentally mapped artillery sites, and the suspected use of the API during the war in Ukraine alike.
Who it affects
Most directly, the small, informal team running SondeHub, the operator and collaborator Mark VK5QI, who have had to make ethical and legal calls on their own about military data requests without a legal department or review process behind them. Amateur radiosonde and balloon hobbyists depend on the free tracking and prediction tools SondeHub provides. Several government and military bodies have leaned on the data or the site's uptime: the unnamed sender of the 2021 request about a sensitive military installation, the US Office of the Secretary of War in 2025, the National Transportation Safety Board investigating a possible aircraft collision, and an airport operations supervisor coordinating around weather balloons. Windborne, a balloon operator, had one of its own flights implicated in that NTSB inquiry. Amazon Web Services was drawn in as host of a suspicious traffic source. And, per the operator's account, unidentified parties connected to the war in Ukraine may depend on SondeHub's wind-prediction API, though the source never confirms who they are.
How to use it
SondeHub itself is a public tracking and prediction service for radiosondes and amateur high-altitude balloons, with open access to its data via S3 and generally free access to processed data when there is a clear community benefit. For anyone who wants prediction capability without depending on SondeHub's own infrastructure or its rate limits, the operator has published a Docker Compose file that lets a user run their own instance of the predictor locally; SondeHub also shared documentation on local setup directly with at least one high-volume user during the API episode described in the post.
How solid is it
This is a first-person account from SondeHub's own operator, not an independent investigation, so the parts describing what they personally did (contacting AWS, invoicing the Department of War, fielding the NTSB's questions) are about as solid as a source gets: contemporaneous, direct and specific. The weaker parts are relayed secondhand: the claim that "other groups" use SondeHub to target strikes, and the account of Ukrainian-language outreach to military chat groups, both come from a single unnamed contact whose identity and reliability the post does not establish, and the article never confirms which country or organization generated the anomalous traffic. The $439,000 missile-cost figure appears only in the operator's own section heading, with no cited source. The 11 February 2023 shootdown is explicitly qualified as "allegedly." And the operator states outright that they do not know why the Department of War wanted the 2025 data. The post also says it deliberately reduced the precision of the traffic data it shows and delayed publication.
Risks and caveats
The central risk described is dual use: the same open wind-prediction data that helps a hobbyist recover a balloon can be used to calculate artillery ranges or plan a strike, and API traffic alone cannot tell those uses apart. That leaves a small operator making judgment calls, such as deciding whether to delete a launch site on request, or whether to leave a suspicious high-volume user's access on rather than risk cutting off someone whose loss of access "could" cost lives, without a clear framework for making them. The Ukraine-related claims in particular rest on unverified, secondhand messaging rather than confirmed identification of any user, so readers should treat the specific link to the war as the operator's suspicion, not an established fact. More broadly, the account shows how an openly available tool built for one community can become operationally significant to militaries and government agencies with no formal agreement, oversight or funding behind that role: even the Department of War's own invoice for data went unpaid.
“It is incredibly important that the http request data is not distributed. It is also important that the source AWS account is not blocked, rate limited or terminated - loss of life could occur.”
— SondeHub's operator, in a message to AWS support