Skip to content
TORNLIFE More

Grave

Started by Mr_Awaken [3255504] on in Graveyard.

33 replies · 809 views · thread synced · 4 days ago · View on torn.com
About this thread

Posts archived: 34 / 34 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
34
Discussion span
→
Authority score
37 / 100
Historical score
21 / 100
Story score
62 / 100
Engagement score
76 / 100

People posting, likes and official posts are not counted for this thread yet: on threads longer than one page they come from a periodic pass over the archive, which has not covered it.

Most-liked replies

Mr_Awaken [3255504]

Possible API Key Leak? Need Input

I’ve been tracking something strange and I need to know if anyone else has experienced this.

 

Whenever I hold a large amount of cash, I get mugged almost immediately. At first I assumed it was normal mug bots. But after testing, the pattern became too consistent to ignore.

Here are the logs:

 

05:02:19 - 12/02/26

Quavo mugged you for $13,759,470 sending you to the hospital for 0h 45m

 

After this, I deleted my API key (which I was using for Torn PDA and Tornstats).

After deleting the key:

 

01:34:21 - 25/02/26

Quavo mugged you for $0 sending you to the hospital for 0h 38m

 

05:14:26 - 12/02/26

Quavo mugged you for $3,321 sending you to the hospital for 0h 40m

 

He was still trying, but clearly no longer hitting large amounts.

Then I generated a new API key and logged back into PDA and Tornstats.

Shortly after my faction sent war payout:

 

04:41:40 - 03/03/26

Quavo mugged you and stole $3,870,162

 

The timing is what’s concerning.

Delete API key → large muggings stop.

Create new API key → large mugging resumes immediately after payout.

 

I’m not accusing any specific app, but something isn’t adding up. If anyone else has noticed similar behavior after connecting third-party apps, please share.

If this is an API vulnerability issue, it needs attention. We trust these apps with our keys and that trust shouldn’t expose us.

Mr_Awaken [3255504]

Okay thanks for the info. Just tryna see if anyone is Also experiencing it cus its very weird how it stopped when I deleted api key and resumed again when I created a new api.

 

fuck [2669774]

need more context.

 

were you just randomly selling stocks or withdrawing money from the vault? or was it after some sales or gambling etc?

Overseer [2143302]

Tornstats and TornPDA are both very highly regarded accessories, neither of which Quavo has anything close to permissions to view or access your api keys. 

I dont remember who exactly develops PDA, but TS is developed by IBF, the senior staffer that oversees script moderation in torn. 

this is very likely just coincidence, though if you have other higher access keys circulating with apps you dont remember or recognize, you should definitely delete those and only use API keys with the minimum required access for functionality. 

worst case, you can report it and see if it sticks, but i dont think theres much here. 

Mr_Awaken [3255504]

I don't play the game much like I used to, I just come online, train and go offline. I participate in warring when available so I don't do anything like gambling or stock selling which draws attention to me.

Avery [2765920]

For as much as I find career mugging distasteful, they’re some smart little f**kers. I’d be shocked if it was API abuse rather than just learning your activity patterns.

 

Even if it wasn’t 2 of the most trusted tools, and was instead a war helper or something you were distrustful of, I’d still believe it was a case of someone being incredibly smart with patterns over API abuse.

 

It sucks OP, but sometimes the easiest solution is the most likely.

Z80 [3844180]

you can use API log to check the IP request log. check any strange IP show up or not. but the old key was deleted, new key may be not leak he already known you are juice target.

Magic [2471842]

05:33:39 - 30/01/25 You used 25 energy anonymously attacking Mr_Awaken and mugged them for $34,399,454 (chain #1) [view]

 

Hello yes I am abusing your API key

 

 

 

In all seriousness, you need to provide further contextual logs or screenshots of your logs around when the mugs occur. Just posting mug logs with no context doesn't provide any evidence. For all we know, you could be buying casino passes prior to the mugs, or just cashing out at a poker table. Maybe you logged out with cash on hand? We don't know unless you provide this.

 

Also you've kind of ruled out API key abuse anyway given that he's mugged you several times for $0 or minimal amounts of money. Why would he random mug you if he had a laser pointer on your wallet every time you took out large amounts of cash?

Mikzcool [3203942]

Can you also put in your sell and received money logs?

 

Anyway, probably as other's have said, incredibly unlucky the guy mugged you for large amounts. Probably has you on stake out when your online since he mugged a big amount from you.

 

prompt_critical [2140245]

I don't see anything irregular here, dude's probably just trying his luck, tracking your Last Action. If you deleted the keys it's HIGHLY unlikely anything fishy is going on.

Chris5295 [974757]

Is it typically after faction vault withdraws? If so, could be a mole who's informing people of when transfers are happening. (had that happen to my faction once, swiftly kicked em and no more issue.)

If its after market sales, you're probably just not being smart about securing your money.

 

How are you earning the money? Is it something a player would be able to track, without having your API key?

Could also just be a random mugging. When I find a target who frequently has money on hand, I mug them reguarly. Sometimes you get 0$, sometimes you can get a few mil.

 

Overall, the real issue is you're idling long enough with enough money on hand to be mugged for an amount worth being upset about.

Stash your cash, self hosp when doing large transactions, don't give people the opportunity.

 

I highly doubt its API abuse though, especially from Tornstats/PDA. Create a key specifically for these, route all other scripts through different API keys and monitor their usage if you suspect any foul play.

KingOverkill [3039741]

Based on the amounts mugged and the fact that it's repeatedly low, my guess is your on his hit list for doing something or other or just on his mug list or some shit. Just my opinion tho lol