Back to overview
Downtime

Third-Party Payment Processor Security Breach

Dec 05 at 01:41pm HST
Affected services
API Performance

Resolved
Dec 14 at 09:39am HST

Crypto payments are now fully updated and have a new payout system. All crypto payments will be immediately delivered to each store's self-owned wallet. SellAuth will no longer provide wallets for its clients, which will prevent this issue from happening again if, in the unlikely event that an attacker were to gain RCE again.

Updated
Dec 09 at 06:20pm HST

Crypto payments and image uploading are back. Every shop has a new temporary wallet while the team focuses on reworking the way crypto payments are handled.

Updated
Dec 08 at 04:30am HST

SellAuth has finished migrating its servers to a new VPS and has decided not to use Next.js for its checkout page due to the RCE vulnerability. However, crypto payments will continue to be unavailable until their team finishes implementing more security around that type of payment. Image uploading is also offline temporarily.

Created
Dec 05 at 01:41pm HST

Our third-party payment processor has suffered a massive security breach caused by the recent React RCE vulnerability.

The attacker used this vulnerability to infiltrate the server and paid out 5% of their client's crypto wallets before they could shut down the crypto nodes and website.