About 218,000 unencrypted private messages posted to the AlphaBay dark web marketplace have been accessed and released to the public, according to several posts on Reddit.
An otherwise unnamed individual going by the handle Cipher0007 posted on Jan. 22 on Reddit that he had warned AlphaBay about two bugs he discovered that gave him access to the private messages of buyers and sellers, that included their names, addresses, the IDs of packs sent from sellers. He posted several several links as proof of his access.
AlphaBay responded in a post left on Pastebin that it verified Cipher00007’s claim and that it has paid Cipher00007 for his finding, closed the loophole and informed those possible affected of the issue. AlphaBay reiterated that all its users should use encryption when posting sensitive information.