bump
trusted trader
Ezlira: forum
Ezlira [4037017] Level 16 Ruined Chaos PF Knight
- Forum posts (Torn's count)
- 2 observed
- Archived posts
- 6
- Threads started (archived)
- 1
Boards
From the 6 newest archived posts.
- Company Recruitment
- Bugs & Issues
- General Discussion
- Trading Post
Threads started
Most-liked posts
Likes as archived at fetch time, adjusted for how long each post had been up. Scored posts only; the full score pass runs after the import.
Hi,
I have discovered a potential API leak/exploit regarding stealth attacks and data exposure.
As you can see in the attached screenshots, when a player (Duncan679) is mugged with a successful stealth attack, the in-game UI correctly masks the attacker's identity, displaying "Mugged by someone".
However, our Discord bot, which pulls hospitalization/attack data from the Torn API, completely bypasses this stealth mechanic and explicitly reveals the attacker's real name (DavidH99) for the exact same event.
Furthermore, to rule out any coincidences, I also verified through the faction logs that the player was not mugged by anyone else during that specific timeframe. This confirms without a doubt that the bot and the in game UI are displaying the exact same attack.
The Issue: The API seems to be leaking the attacker's identity even when the attack was a successful stealth attack. This effectively renders the stealth mechanic useless, as anyone with a Discord bot or API access can easily see who attacked them.
Proof:
-
Image 1: Bot correctly parsing the API and showing the exact attacker (DavidH99).
-
Image 2: In-game profile showing the attacker is hidden as "someone".
Could you please look into why the API is exposing stealth attacker data? Let me know if you need more details or specific API logs.
Recent archived posts
Hi again,
I tried to retrieve the historical raw JSON for that specific attack, but I am unable to provide it for two reasons:
-
Our bot processes the API data in real-time and we strictly do not store or keep logs of raw JSON payloads to save storage and respect privacy.
-
I attempted to manually fetch the past attack log via the
/user/4130073?selections=attacksendpoint using my API key, but I received an HTTP 403: Forbidden error (which is expected, as the API restricts viewing other players' attack histories retroactively).
However, the screenshot I provided in the original post is a direct output of what the API delivered to our bot at that exact timestamp. The bot simply maps the attacker_name and attacker_id fields. If the attack was properly stealthed at the API level, those fields should have been empty or masked, but they clearly weren't.
Moving Forward: I have now added a temporary logging mechanism to our bot's code. The very next time a stealth mug happens within our scope, I will capture the exact raw JSON payload and share it here for your debugging process.
Please let me know if the current screenshots are enough for your team to investigate the /faction/ or /user/ endpoint logic, or if you prefer to wait for my next raw data catch.
Hi,
I have discovered a potential API leak/exploit regarding stealth attacks and data exposure.
As you can see in the attached screenshots, when a player (Duncan679) is mugged with a successful stealth attack, the in-game UI correctly masks the attacker's identity, displaying "Mugged by someone".
However, our Discord bot, which pulls hospitalization/attack data from the Torn API, completely bypasses this stealth mechanic and explicitly reveals the attacker's real name (DavidH99) for the exact same event.
Furthermore, to rule out any coincidences, I also verified through the faction logs that the player was not mugged by anyone else during that specific timeframe. This confirms without a doubt that the bot and the in game UI are displaying the exact same attack.
The Issue: The API seems to be leaking the attacker's identity even when the attack was a successful stealth attack. This effectively renders the stealth mechanic useless, as anyone with a Discord bot or API access can easily see who attacked them.
Proof:
-
Image 1: Bot correctly parsing the API and showing the exact attacker (DavidH99).
-
Image 2: In-game profile showing the attacker is hidden as "someone".
Could you please look into why the API is exposing stealth attacker data? Let me know if you need more details or specific API logs.
bump
trusted trader
found
- Manual labor: 2.162
- Intelligence: 521
- Endurance: 4.738
- Total 7.421
looking for trains message me to discuss prices
Hey! Nice thread idea 🙂
I’m from Turkey. Been playing Torn for a while now and it’s honestly cool to see how global the community is. I never expected players from so many different countries when I first started.
Torn really does reach everywhere. Cheers from Turkey and good luck in-game!🇹🇷🇹🇷

