Twitch Gets Gutted - All Source Code Leaked

Опубликовано: 24 Июль 2026
на канале: CSI digital
215
6

Twitch Gets Gutted - All Source Code Leaked
Original article: https://threatpost.com/twitch-source-...
An attacker claims to have ransacked Twitch for everything it’s got, including all of its source code and user-payout information.
Twitch has confirmed the breach.
According to Video Games Chronicle (VGC), which first reported the assault on the interactive live-streaming service, an anonymous user posted a link to a 125GB torrent to 4chan on Wednesday.
Whoever’s responsible for gutting the service that’s near and dear to gamers’ hearts rationalized it by saying that the Twitch community needs to have the wind knocked out of its lungs. They called the leak a means to “foster more disruption and competition in the online-video streaming space,” because “their community is a disgusting toxic cesspool.”
S/he’s not all wrong, by Twitch’s own admission.
In August, Twitch responded to what it described as “botting, hate raids and other forms of harassment targeting marginalized creators.


Twitch said that it had identified and patched a vulnerability in its “proactive” filters that should help it to better detect hate speech in chat. It also said at the time that it was planning to launch channel-level ban-evasion detection and account-verification improvements later this year.

Multiple outlets, including VGC and The Verge, as well as one of VGC’s anonymous company sources, have verified that the data thief got away with the real deal: All the files mentioned on 4chan are legitimate and are publicly available to download.
That includes the source code for Twitch, which is owned by Amazon.
VGC provided this list of what’s in the data dump:
• The entirety of Twitch’s source code with comment history “going back to its early beginnings”
• Creator-payout reports from 2019
• Mobile, desktop and console Twitch clients
• Proprietary SDKs and internal AWS services used by Twitch
• “Every other property that Twitch owns” including IGDB and CurseForge
• An unreleased Steam competitor, codenamed Vapor, from Amazon Game Studios
• Twitch internal “red-teaming” tools (designed to improve security by having staff pretend to be hackers)

“This leak is very serious for Twitch, but the question is what effects this will have for the regular Twitch user,” Niemela said.
At first glance, this looks like a direct attack against Twitch only, rather than its users. Still, it’s “almost guaranteed” that user information will have been swept up in this breach, according to Archie Agarwal, founder and CEO at the threat-modeling provider ThreatModeler.
“That means that users will have to take the usual precautions of changing their account credentials and making sure they don’t use the same combination of credentials to access other services online,” he told Threatpost via email.
That’s particularly true given that this breach, as nasty and sprawling as it is, is apparently just the start. The 4chan leak was labeled as “part 1,” suggesting that there’s more to come.


Agarwal told Threatpost that breaches don’t get any worse than this one.
“Reading of a data breach that includes the entire source code, including unreleased software, SDKs, financial reports and internal red-teaming tools will send a shudder down [the spine of] any hardened infosec professional,” he said. “This is as bad as it could possibly be.”
If zero alarms went off, that clearly means that something’s not right with Twitch’s security setup, Agarwal suggested.
“The first question on everyone’s mind has to be: How on earth did someone exfiltrate 125GB of the most sensitive data imaginable without tripping a single alarm?” he asked. “There’s going to be some very hard questions asked internally.”

Chappell told Threatpost that the 128GB torrent appears to have been acquired from one of Twitch’s internal GitHub repositories. The leaked data was then made available through torrents shared as magnet links, Chappell said.
“There appears to be evidence that the original files came from an internal GitHub server, git-aws.internal.justin.tv,” he added, noting that Justin.tv was the name of the company that eventually became Twitch.
“It rebranded as Twitch in 2011 — so this looks like a long-standing piece of infrastructure,” Chappell speculated.
If the leak does get tracked back to GitHub, Twitch will find itself in good company: Microsoft’s GitHub account was ransacked back in 2020.

Javvad Malik, security awareness advocate at KnowBe4, told Threatpost that beyond changing passwords, Twitch streamers should also keep an eye out for future phishing attempts that build on whatever data has been leaked or will be leaked.
“Changing passwords, especially if the same password has been used on other systems, is a good first step for affected users,” he commented. “But it’s also worth bearing in mind that not all attacks based on information on these leaks will come immediately.”