Third-Party Payment Processor Security Breach
Resolved
Dec 14 at 09:39am HST
Crypto payments are now fully updated and have a new payout system. All crypto payments will be immediately delivered to each store's self-owned wallet. SellAuth will no longer provide wallets for its clients, which will prevent this issue from happening again if, in the unlikely event that an attacker were to gain RCE again.
Affected services
Updated
Dec 09 at 06:20pm HST
Crypto payments and image uploading are back. Every shop has a new temporary wallet while the team focuses on reworking the way crypto payments are handled.
Affected services
Updated
Dec 08 at 04:30am HST
SellAuth has finished migrating its servers to a new VPS and has decided not to use Next.js for its checkout page due to the RCE vulnerability. However, crypto payments will continue to be unavailable until their team finishes implementing more security around that type of payment. Image uploading is also offline temporarily.
Affected services
Created
Dec 05 at 01:41pm HST
Our third-party payment processor has suffered a massive security breach caused by the recent React RCE vulnerability.
The attacker used this vulnerability to infiltrate the server and paid out 5% of their client's crypto wallets before they could shut down the crypto nodes and website.
Affected services