bf.st Full Codebase and Database Allegedly Offered for Sale
A forum actor posting as mrwho is offering what they claim is the full bf.st codebase and database. The actor says the forum was compromised around late May or early June 2026 through a vulnerability in its forum implementation while the site was launching. As evidence, the post includes a database table listing showing 128 tables and a sample of rows from the users table. The visible schema includes account and authentication-related fields such as usernames, email addresses, password values, salts, login keys, registration and activity timestamps, user groups, profile data, warning data, private-message related fields, two-factor authentication fields and security-question fields. The actor also advertises a tree-file sample for the codebase and states that payment is XMR only. The claim is unverified.
▣Post details
!What the post claims
- Full bf.st codebase
- Full bf.st database
- Compromise during the forum's launch period
- Vulnerability in the forum implementation
- Claimed breach in late May or early June 2026
- 128 database tables shown
- User-account records
- Usernames
- Email addresses
- Password values
- Password salts
- Login keys
- Registration dates
- Last-active and last-visit data
- User groups and permissions
- Profile fields and profile metadata
- Private-message related fields
- Warnings and reputation-related fields
- Two-factor authentication fields
- Security-question fields
- Forum sessions and login-attempt data
- Moderator and admin-related tables
- Credits and crypto-invoice tables
- Codebase tree-file sample advertised
- XMR-only payment
◱Screenshots
☷Mapped techniques
The actor only states that a vulnerability in the forum implementation was used during the site's launch. The exact flaw and exploitation path are not disclosed, so the mapping below remains high level.
- Initial Access T1190 Exploit Public-Facing Application Claimed The actor claims a vulnerability in the forum implementation was used to breach bf.st around late May or early June 2026.
- Collection T1213 Data from Information Repositories Claimed The listing claims the full database was obtained and shows a large set of forum tables containing user, session, moderation, private-message and account-related data.
⚠Potential impact
If authentic, exposure of both the full codebase and the underlying forum database could create significant risk for the platform and its members. Source code may reveal implementation weaknesses, internal logic, undocumented functionality or secrets that could support follow-on attacks. The database schema shown in the post includes password-related fields, login keys, two-factor authentication data, security-question fields, email addresses, private-message related data and session information, which could increase the risk of account takeover, deanonymization, credential attacks and targeted phishing. A complete database leak could also expose historical moderation, reputation, credits, transactions and other operational records.
iStatus Unverified
The forum post includes a large database-table listing and sample output from the users table, and the actor claims responsibility for an earlier compromise during bf.st's launch period. However, the post does not identify the specific vulnerability, provide independent proof that the entire codebase and database are complete, or demonstrate that any access remains active. Dark Web Informer has not independently verified the breach, the claimed 128-table database, the source-code archive or the authenticity and completeness of the user records.
Dark Web Informer // Threat Intelligence