CURRENT MISSION: Conclude the 2026 soyjak.party hack page, aswell as any pages relating to it, such as the Summer 2026 Crisis page.
Update Quotecord with any relevant info. See the blackboard for more info.

Talk:2026 soyjak.party hack

From Soyjak Wiki, the free ensoyclopedia
Jump to navigationJump to search

Findings

TL;DR: Server was hacked, guy is legit.

I inspected the leak in a DFIR OS. The leak is genuine. The archive contains a Git working tree whose remote is ssh:/git.soyjak.st/quote/soyjakparty. The local Git identity belongs to Quote. There is also a 72 KB inc/instance-config.php, along with runtime/install material.

Most of the files are timestamped August 5, 2026 at ~22:51 UTC or earlier, consistent with a bulk copy/archive operation. The guy also left behind an untracked README which states:

"I'm quote and my opsec is garbage, here is the source code of my entire site.
H*cked by anonymous ~ 2026 08 05"

The README was written on August 11, while everything else examined so far is timestamped August 5 or earlier. Taking it all into account, this is a smoking gun.

Ask me any questions you have below. I don't have the time to write the full article myself as I'll be busy soon. I'll investigate more later. P.S. for some reason, there's minecraft player data in the server. Rickert (talk) 09:38, 11 August 2026 (UTC)

There's a untracked file named gzip_bomb.gz. Its a (small) decompression bomb. The file is dated June 27, 2026, so it predates the August hack. Not sure what its doing there. Rickert (talk) 09:57, 11 August 2026 (UTC)
is it actually a bomb? --Gem Gem (talk) 10:08, 11 August 2026 (UTC) 10:08, 11 August 2026 (UTC)
if you extract it it'll go from 1mb to 1gb, all zeros. that's why I said it's small. Serious ones go for petabytes to put things into context. Seems to be irrelevant tbh, just surprised its there. Rickert (talk) 10:12, 11 August 2026 (UTC)
The server was last operational at August 5, at 18:01 UTC. The copywrite happened around ~22:51 UTC as mentioned earlier, meaning the hacker had full access to the server for some quite time. "Around August 5, 18:00 UTC" https://soyjakwiki.org/2026_outage. Rickert (talk) 10:30, 11 August 2026 (UTC)
18:00 1 file 18:01 1 file 22:51 4,004 files Rickert (talk) 10:33, 11 August 2026 (UTC)
366 22:51:32 722 22:51:33 1892 22:51:34 1024 22:51:35 he got it all in 4 seconds. Rickert (talk) 10:35, 11 August 2026 (UTC)
no way kek --Gem Gem (talk) 10:39, 11 August 2026 (UTC) 10:39, 11 August 2026 (UTC)
this shit just keeps getting wackier geeeeeg i'd say the minecraft player data probably has something to do with soycraft / /craft/ JDS1948 (talk) 10:41, 11 August 2026 (UTC)
That weird telegram thing has one voice message in it, but upon listening its just some random fan noise. No talking o algo. Rickert (talk) 10:59, 11 August 2026 (UTC)
Overall, its hard to establish any conclusions, but I can't rule out that it was Quote himself, there's really nothing pointing to a sudden compromise and nuke that explains the shutdown, doe I haven't checked for the alleged ki starting point to see if something originated from there, yet. TL;DR I have yet to encounter any attacker evidence (other than the copy, which doesn't establish anything identity wise). Don't take this and start spreading it everywhere that it was Quote who did it, as I said, there's nothing to prove it, or prove otherwise. 2/10 odds best Rickert (talk) 11:12, 11 August 2026 (UTC)
The hacker claims to be Russian. --Gem Gem (talk) 11:22, 11 August 2026 (UTC) 11:22, 11 August 2026 (UTC)
README timestamp is 2026-08-11 04:16:39 UTC, then in Moscow time (UTC+3) it was August 11, 2026 at about 7:16 AM, when he wrote it. Rickert (talk) 11:27, 11 August 2026 (UTC)
5 in the morning also discredits the notion that its Quote, unless hes a night owl. Rickert (talk) 11:29, 11 August 2026 (UTC)
There's 58 files that had their filesystem metadata change, however their timestamps did not change at 22:49 (2 mins before). possibly this Russian checking if he can start his op o algo or a little fuckup. My guess is he got access to the SSH at this point. Rickert (talk) 12:33, 11 August 2026 (UTC)

Compromised

Be warned that a huge amount of IPs (a grand total of 59,216) have been all leaked. Rickert (talk) 11:43, 11 August 2026 (UTC)

yeah that one's kind of to be expected, do you know how extensive it is (how long it gets stored, how many as a percentage of posters)? JDS1948 (talk) 11:45, 11 August 2026 (UTC)
Whatever is logging it claims its all since 2023. I can't establish what it is for exactly yet. Rickert (talk) 11:47, 11 August 2026 (UTC)
It might be an external IP dataset rather than a dump of Sharty users. None of the addresses tested across the full leak appear elsewhere except for... wait for it... 67 that overlap the included Tor exit-node lists. A random IP I looked up was a Pakistani residential IP doe. One was a VPN, other four were datacenters. Sixth check is a US vpn, seventh is an Austrian residential... hmm... I'll elaborate more in a bit {{e|neutral}} Rickert (talk) 11:55, 11 August 2026 (UTC)
One reported "Services:VPN Server Forum spam source (8) Country:Indonesia" Rickert (talk) 11:58, 11 August 2026 (UTC)
TL;DR its a global list of IPs that mostly return VPN or data center, but there are also residentials mixed in. Make what you will from that. Indian, Pakistani, Brazilian IPs seem to pop up a lot and never report VPN, might have to do with the Brownocaust. Rickert (talk) 12:03, 11 August 2026 (UTC)
probably a blacklist/greylist of some kind then, maybe the main one or just one list of multiple. could you tell me if there are any israeli ips in there? (or anywhere else in the src) not in a "I NEED TO FIND THE CONNECTION BETWEEN THIS AND DA JOOZ" way it's cuz whenever I connected to the sharty without my proxy/vpn it wouldn't block me from posting + i saw IL on /soy/ and /int/ (which could be vpns) despite a bunch of people saying that israeli ips were blocked from posting which i'm still confused about JDS1948 (talk) 12:21, 11 August 2026 (UTC)
No. I didn't bother to check more than ~ 20 though. Rickert (talk) 12:23, 11 August 2026 (UTC)

marge

I honestly can't make sense of any of this, soysurgency happens, site goes down with cftunnel 1033 then 503 host for a few days, the sites come back incrementally, there's a disk problem and a fuckton of images but only images are lost, someone hacked it on the 5th the same day it started, when the site goes back up there's a new owner and the site turns into a battlefield with gore running rampant. doesn't seem like anyone knows what the fuck is going on, quote is silent, salt or whoever this nuadmin is isn't saying much. literally no one who'd be in the loop seems to know whats going on/is saying anything. Even this wiki's chain of command and order of things seems to have fallen apart. Well I wouldn't say entirely, but shit's getting done at a slower pace and everything's more dispersed JDS1948 (talk) 11:44, 11 August 2026 (UTC)

>quote is inactive
>many jannycords get leaked
>soysurgencies (protests against admins) happen all around
>quote becomes even more inactive
>sharty starts to get ddosed by foodists who were ddosing kiwifarms previously (you'd get a cloudflare check every time you've changed an IP on the shiki and sharty)
>quote gives up, and sells the sharty to his IRL friend (named by soyteens as salt) for $25000 after meeting in a pub in london
>while changing the site's ownership, quote fucks up and opens a window for some kiwicaca to hack the sharty
>quote and salt shut down the soysphere
>quote and salt were able to get it back, first the booru, then the wiki then the sharty
the explanation (for this event) is that somehow the Russian very likely acquired Quote's SSH credentials, somehow caused the servers to go down (this is all unknown, nothing in this leak can prove anything about this), most likely also somehow caused the Wiki to have some data corruption. Then, he waited till 22:49 UTC or a bit earlier (makes sense, 23:49 is bedtime in the UK), and proceeded to yoink everything by 22:51 (or a bit after). The issue is he already caused damage and shutdown way before 22:49 and it wasn't late in the UK, so Quote could've noticed it if he wasn't a DNB and easily intervened SSH-wise before it all got downloaded. As for why it took the Russian so long, maybe he was doing something else till 22:49, idk. Regardless, there's nothing else after this in the leak metadata wise because his goal was to acquire the source code, so no reason for any further activity, except for his little README, and the source code isn't that interesting really. Rickert (talk) 13:34, 11 August 2026 (UTC)
It is a very unimpressive and boring attack by the guy, other than causing it to shutdown and download the source code (of a vibe-coded fork of something already public). Even the IP leaks aren't that interesting because its a blocklist and doesn't point to much. Rickert (talk) 13:37, 11 August 2026 (UTC)
He was probably hiding from drone attacks or gooning to 'p or something Gzard (talk) 13:43, 11 August 2026 (UTC)
{{e|fact}} Rickert (talk) 13:44, 11 August 2026 (UTC)
can we rule out nuadmin/salt being the hacker or being a beneficiary of this guy? JDS1948 (talk) 14:02, 11 August 2026 (UTC)
By the fact that it doesn't make sense, yes. Like I said, neither the attack nor the outcome is anything impressive. Most damage he did was wipe the wiki gallery, and even that has been mostly resolved and recovered (and is still being worked on)by a certain editor with a red username . Rickert (talk) 14:15, 11 August 2026 (UTC)
It's odd that they haven't extracted mysql db. They likely have it but haven't released it yet. --Gem Gem (talk) 15:39, 11 August 2026 (UTC) 15:39, 11 August 2026 (UTC)
Could be, but we can't verify for sure with what we have. I did also see the RCE claim, and there was an issue with ffmpeg RCE a few months ago, but I don't know. Rickert (talk) 16:05, 11 August 2026 (UTC)

Reupload

Can someone upload the leak on Internet Archive or catbox or just link the gofile? I can't access kiwifarms at the moment Soyjaklover2025 (talk) 14:11, 11 August 2026 (UTC)

noob — Preceding unsigned comment added by Gzard (talkcontribs)
https://gofile.io/d/yvcLP6 here you go nusoi JDS1948 (talk) 14:15, 11 August 2026 (UTC)
thanks Soyjaklover2025 (talk) 14:25, 11 August 2026 (UTC)

Patched version

I have released a patched version of the leak just to make it more easier for nusois to get it running.

where
@User:AlsoCharlieKirk ~Chud25136 (talk) 18:14, 14 August 2026 (UTC)

Page title

@User:Gem why do you think the page title should be "2026 Hack" instead of "2026 hack"? MOS says that "page names should avoid needless capitalization" and pages like 2026 outage don't use capitalization 'kiGOD (talk) 21:28, 11 August 2026 (UTC)

alright you can revert it. I generally think event names should be capitalized though. (e.g. The Great Cuckset) --Gem Gem (talk) 21:37, 11 August 2026 (UTC) 21:37, 11 August 2026 (UTC)
actually now that I look at it, most events were capitalized except for 2026 outage. --Gem Gem (talk) 21:41, 11 August 2026 (UTC) 21:41, 11 August 2026 (UTC)

change page title to 2026 soyjak.st hack

or 2026 sharty hack because this did not happen under .party domain whatsoever Aiden's husband (talk) 08:46, 17 August 2026 (UTC)

SNCA doe. ChuderinoBino (talk) 10:38, 17 August 2026 (UTC)