Write the reason you're deleting this FAQ
What happened
On August 28-29 attackers used the Onyx exploit to compromise our Proxmox virtualization hosts.
Their access was to the hypervisor layer only - not the virtual machines running the site.
Rather than access data, the attackers corrupted every VM, taking the site down.
What was NOT affected
Our server team found no evidence that any data was viewed, downloaded, or stolen - the attackers had access to the Proxmox hosts, not the VMs where site data lives.
No card data was at risk: payments are processed by PayPal, Stripe, and our other gateways, and card numbers are never stored on our servers.
Impact
Full site outage on August 28-29 while systems were rebuilt.
The database was restored from the August 28 backup, losing roughly 24 hours of activity (orders, payments, withdrawals, and signups from that window).
What we did
Rebuilt the virtual machines and restored the site from backups.
Forced a precautionary password reset for every user and administrator at next login, even though there is no evidence credentials were exposed.
Replaced all legacy encryption with modern authenticated encryption (AES-256) and began re-encrypting stored files.
Notified all users by email and site notice, and asked sellers to resend recent IPN data.
We are recovering lost-window orders, payments, and withdrawals from gateway records and support reports - most reported cases are re-created within a day.
Current status
The site is fully operational.
Individual recoveries continue as users report them.
Infrastructure hardening and monitoring improvements are ongoing.
Missing an order, payment, or withdrawal from August 28-29? Contact support with the transaction ID or receipt and we will restore it.