Skip to content

BF Full Codebase and Database Allegedly Offered for Sale

Breach Report Source Code & Database Forum Infrastructure XMR Only

bf.st Full Codebase and Database Allegedly Offered for Sale

A forum actor posting as mrwho is offering what they claim is the full bf.st codebase and database. The actor says the forum was compromised around late May or early June 2026 through a vulnerability in its forum implementation while the site was launching. As evidence, the post includes a database table listing showing 128 tables and a sample of rows from the users table. The visible schema includes account and authentication-related fields such as usernames, email addresses, password values, salts, login keys, registration and activity timestamps, user groups, profile data, warning data, private-message related fields, two-factor authentication fields and security-question fields. The actor also advertises a tree-file sample for the codebase and states that payment is XMR only. The claim is unverified.

Sponsored
Database tables128
CodebaseFull
DatabaseFull
PaymentXMR only

Post details

Targetbf.st
SectorOnline forum
ListingSource code + database sale
Claimed scopeFull codebase and database
Database tables128
Claimed breach windowLate May / early Jun 2026
Observed
Actormrwho

!What the post claims

  • Full bf.st codebase
  • Full bf.st database
  • Compromise during the forum's launch period
  • Vulnerability in the forum implementation
  • Claimed breach in late May or early June 2026
  • 128 database tables shown
  • User-account records
  • Usernames
  • Email addresses
  • Password values
  • Password salts
  • Login keys
  • Registration dates
  • Last-active and last-visit data
  • User groups and permissions
  • Profile fields and profile metadata
  • Private-message related fields
  • Warnings and reputation-related fields
  • Two-factor authentication fields
  • Security-question fields
  • Forum sessions and login-attempt data
  • Moderator and admin-related tables
  • Credits and crypto-invoice tables
  • Codebase tree-file sample advertised
  • XMR-only payment

Screenshots

Forum post offering the alleged bf.st full codebase and database, observed 16 September 2026.

Mapped techniques

The actor only states that a vulnerability in the forum implementation was used during the site's launch. The exact flaw and exploitation path are not disclosed, so the mapping below remains high level.

  • Initial Access T1190 Exploit Public-Facing Application Claimed The actor claims a vulnerability in the forum implementation was used to breach bf.st around late May or early June 2026.
  • Collection T1213 Data from Information Repositories Claimed The listing claims the full database was obtained and shows a large set of forum tables containing user, session, moderation, private-message and account-related data.

Potential impact

If authentic, exposure of both the full codebase and the underlying forum database could create significant risk for the platform and its members. Source code may reveal implementation weaknesses, internal logic, undocumented functionality or secrets that could support follow-on attacks. The database schema shown in the post includes password-related fields, login keys, two-factor authentication data, security-question fields, email addresses, private-message related data and session information, which could increase the risk of account takeover, deanonymization, credential attacks and targeted phishing. A complete database leak could also expose historical moderation, reputation, credits, transactions and other operational records.

iStatus Unverified

The forum post includes a large database-table listing and sample output from the users table, and the actor claims responsibility for an earlier compromise during bf.st's launch period. However, the post does not identify the specific vulnerability, provide independent proof that the entire codebase and database are complete, or demonstrate that any access remains active. Dark Web Informer has not independently verified the breach, the claimed 128-table database, the source-code archive or the authenticity and completeness of the user records.

Dark Web Informer // Threat Intelligence

Latest