Typing this up quickly on my laptop that I snuck into work for the day, so excuse any rushed tone in this announcement. I'm not bothering with formatting, so sorry if the post isn't pretty. And sshhhh.
As a lot of you know, TornW3B was compromised yesterday. If you navigated to the site and clicked anywhere you were redirected to some scammy crypto site. This was because of a script being injected into the header that caused a pop-under to render across all of the pages. It didn't happen on every click, which I suspect was something done intentionally in an attempt to not seem overly obvious. Still pretty obvious if you ask me, but, moving on..
While most of you have been supportive of my struggles during this time with my platform, and I want to thank all of you for that, I have seen a few voicing doubts. I'll admit, they're not entirely unfounded. At the end of September last year, my site was severely compromised, and then just about three months later, it happens again?
Yeah, that would seem pretty suspicious. I'd be raising an eyebrow too. But this isn't that. At least not exactly.
The previous incident, based on the evidence I had available, stemmed from the firewall failing (or ServerOptima failing, I guess I should say) and granting someone direct access into my server at that time. They'd done a lot of damage and managed to hide their tracks.
Since then, I hardened security. I installed several security and monitoring tools. If anything happened on the server that wasn't from my IP directly, I received either a message about it in Discord or an email.
This is why I had been fine leaving the server up and running despite the redirects occurring, because I could tell by my logs that my server still appeared to be secured. But I was at work and many hours from the nearest computer, so there was nothing I could do about it until I got home. After much discussion with members of Torn staff and Glasnost (who continues to serve as an advisor for my platform) I decided to bring down the site.
Not because of security issues with the site, but because of the nature of the website users were being redirected to: a crypto scam and phishing site. The redirect itself wasn't harmful.
When I got home, I didn't even take off my shoes. I spent hours scanning every corner of my codebase, looking for anything that had been tampered with. Nothing.
There was no SSH access beyond my own and Glasnost's. No files had been modified. Nothing was installed on my server. The database, which logs all connections and disconnections, showed nothing abnormal. Nothing to indicate any tampering whatsoever.
So I proceeded with diagnosing the redirects once I was confident there was nothing obvious that would cause damage if I spun the server back up. I configured my firewall to block access to everyone except my IP, spun it back up, and visited the site. Redirects were still occurring. So I shut down the server again. I cleared my Next.js cache and rebuilt. Tried again. Redirects had stopped completely.
Theoretically speaking, I probably could have relaunched the server at this point and done nothing more. But prior to diagnosing the issue, I was on Next.js version 16.0.0, which is subject to vulnerability CVE-2025-66478.
While my symptoms didn't seem entirely consistent with everything reported there, that was the only possible entry point I could find after spending half my night digging through configs, binaries, and whatever else they could have possibly touched. So I decided to backup my database and perform a full wipe of the server. If there was even the slightest chance someone had root access and was just trying to remain stealthy, I didn't want to take that chance. I could have been pwnd already and not even know it.
After wiping, I restored my source code from a commit that was created prior to when the attack seemed to begin. I updated every package and audited them to ensure no vulnerabilities remained. I tightened a few configurations as well, just because at this point I'm beyond paranoid.
But if you still don't have trust in the platform after this, you are welcome to feel that way. I'm not forcing anyone to use TornW3B. I make no money from this, and I hardly even use my own platform..mainly due to real life time constraints. Still, there is no cause for alarm. I don't believe anything major was compromised, and yes, that includes your API keys. But you are also welcome to rotate your API key if you just want to be sure, in the same way that I had wiped my server just to be sure.
This is a hobby project that I did for my love of the community, and I will continue to work on it and improve it as long as I can because I just love doing it, and I love seeing people enjoy what I created.
That being said, I have been monitoring W3B very closely all day and see no reason to suspect any breach remains and feel confident in saying that I am moving TornW3B from a soft relaunch to a full relaunch.
Love you all and thank you again <3