CURRENT MISSION: Conclude the 2026 soyjak.party hack page, aswell as any pages relating to it, such as the Summer 2026 Crisis page.
Update Quotecord with any relevant info. See the blackboard for more info.

Talk:2026 soyjak.party hack: Difference between revisions

From Soyjak Wiki, the free ensoyclopedia
Jump to navigationJump to search
Rickert (talk | contribs)
No edit summary
Tag: tor
Rickert (talk | contribs)
Tag: tor
Line 22: Line 22:


: That weird telegram thing has one voice message in it, but upon listening its just some random fan noise. No talking o algo. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 10:59, 11 August 2026 (UTC)
: That weird telegram thing has one voice message in it, but upon listening its just some random fan noise. No talking o algo. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 10:59, 11 August 2026 (UTC)
: Overall, its hard to establish any conclusions, but I can't rule out that it was Quote himself, there's really nothing pointing to a sudden compromise and nuke that explains the shutdown, doe I haven't checked for the alleged ki starting point to see if something originated from there, yet. TL;DR I have yet to encounter any  attacker evidence. Don't take this and start spreading it everywhere that it was Quote who did it, as I said, there's nothing to prove it, or prove otherwise. 2/10 odds best [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:12, 11 August 2026 (UTC)

Revision as of 11:12, 11 August 2026

Findings

TL;DR: Server was hacked, guy is legit.

I inspected the leak in a DFIR OS. The leak is genuine. The archive contains a Git working tree whose remote is ssh:/<censored cause I don't want trouble>/quote/soyjakparty. The local Git identity belongs to Quote. There is also a 72 KB inc/instance-config.php, along with runtime/install material.

Most of the files are timestamped August 5, 2026 at ~22:51 UTC or earlier, consistent with a bulk copy/archive operation. The guy also left behind an untracked README which states:

"I'm quote and my opsec is garbage, here is the source code of my entire site.
H*cked by anonymous ~ 2026 08 05"

The README was written on August 11, while everything else examined so far is timestamped August 5 or earlier. Taking it all into account, this is a smoking gun.

Ask me any questions you have below. I don't have the time to write the full article myself as I'll be busy soon. I'll investigate more later. P.S. for some reason, there's minecraft player data in the server. Rickert (talk) 09:38, 11 August 2026 (UTC)

There's a untracked file named gzip_bomb.gz. Its a (small) decompression bomb. The file is dated June 27, 2026, so it predates the August hack. Not sure what its doing there. Rickert (talk) 09:57, 11 August 2026 (UTC)
is it actually a bomb? --Gem Gem (talk) 10:08, 11 August 2026 (UTC) 10:08, 11 August 2026 (UTC)
if you extract it it'll go from 1mb to 1gb, all zeros. that's why I said it's small. Serious ones go for petabytes to put things into context. Seems to be irrelevant tbh, just surprised its there. Rickert (talk) 10:12, 11 August 2026 (UTC)
The server was last operational at August 5, at 18:01 UTC. The copywrite happened around ~22:51 UTC as mentioned earlier, meaning the hacker had full access to the server for some quite time. "Around August 5, 18:00 UTC" https://soyjakwiki.org/2026_outage. Rickert (talk) 10:30, 11 August 2026 (UTC)
18:00 1 file 18:01 1 file 22:51 4,004 files Rickert (talk) 10:33, 11 August 2026 (UTC)
366 22:51:32 722 22:51:33 1892 22:51:34 1024 22:51:35 he got it all in 4 seconds. Rickert (talk) 10:35, 11 August 2026 (UTC)
no way kek --Gem Gem (talk) 10:39, 11 August 2026 (UTC) 10:39, 11 August 2026 (UTC)
this shit just keeps getting wackier geeeeeg i'd say the minecraft player data probably has something to do with soycraft / /craft/ JDS1948 (talk) 10:41, 11 August 2026 (UTC)
That weird telegram thing has one voice message in it, but upon listening its just some random fan noise. No talking o algo. Rickert (talk) 10:59, 11 August 2026 (UTC)
Overall, its hard to establish any conclusions, but I can't rule out that it was Quote himself, there's really nothing pointing to a sudden compromise and nuke that explains the shutdown, doe I haven't checked for the alleged ki starting point to see if something originated from there, yet. TL;DR I have yet to encounter any attacker evidence. Don't take this and start spreading it everywhere that it was Quote who did it, as I said, there's nothing to prove it, or prove otherwise. 2/10 odds best Rickert (talk) 11:12, 11 August 2026 (UTC)