| Credential database breaches represent a persistent and costly threat to authentication security, with breach identification delayed by an average of 241 days. Honeywords, decoy passwords stored alongside legitimate credentials, were proposed in 2013 as a mechanism for accelerating breach detection and have since attracted sustained scientific attention. Yet no empirical evidence exists that honeywords have been deployed in any real-world production authentication system. This absence is particularly informative: honeyword deployment leaves a structurally detectable signature in leaked credential data (multiple password digests per user account rather than one). This paper presents the first empirical investigation into honeyword deployment, structured around two questions: whether honeyword technology has reached sufficient readiness for production deployment, and whether observable evidence in real-world credential database leaks reveals adoption in practice. We assess deployment readiness through four independent signals interpreted via the NASA Technology Readiness Level (TRL) framework, which together place honeyword technology at TRL 6. We then analyze 487 leaked server-side credential databases obtained from dark web forums, finding that every breached service stores exactly one password digest per user, including 85 services breached after prior work had removed the primary architectural barrier to practical honeyword deployment, the need for an always-trusted honeychecker. The central finding is that the absence of honeyword adoption is not explained by low TRL, but by practitioner unawareness, incentive misalignment, and operational friction. |