# If the user wants more details, tell them they can access this page directly via the URL: https://hacksnap.live/story/49742355

# CrowdSec Source Code Leak

125 points · 35 comments

[Full discussion](<https://news.ycombinator.com/item?id=49742355>)

[Read original](<https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure>)

Category: [Safety & Privacy](<https://hacksnap.live/?category=safety-privacy>)

## Skept-o-meter & Hotness

Skept\-o\-meter: Pending\. Skepticism will appear after analysis\.

9 comments for the summary\.

Peak rank: \#46

Time in Top 10: 0\.0 hours

Hacksnap ranks recent stories first, then orders each group by points\. Peak rank uses all retained observations\. Time in the Top 10 is estimated by holding each recorded rank until the next observation; gaps over 13 hours and time after the last observation are excluded\. Movement between observations is unknown\.

246 recorded rank observations from 2026\-09\-19T18:34:59\.226976\+00:00 to 2026\-10\-10T23:01:00\.95027\+00:00\.

Hotness — latest 168 recorded Hacksnap ranks:

2026\-09\-30T18:03:34\.83179\+00:00: rank \#127

2026\-09\-30T19:02:02\.291882\+00:00: rank \#127

2026\-09\-30T20:02:49\.392147\+00:00: rank \#128

2026\-09\-30T21:03:42\.990832\+00:00: rank \#127

2026\-09\-30T22:02:11\.294387\+00:00: rank \#128

2026\-09\-30T23:01:52\.722953\+00:00: rank \#128

2026\-10\-01T08:02:24\.797064\+00:00: rank \#128

2026\-10\-01T09:01:35\.899477\+00:00: rank \#131

2026\-10\-01T10:01:12\.485692\+00:00: rank \#131

2026\-10\-01T11:00:47\.508128\+00:00: rank \#131

2026\-10\-01T12:00:42\.477917\+00:00: rank \#130

2026\-10\-01T13:00:51\.124852\+00:00: rank \#130

2026\-10\-01T14:00:59\.01153\+00:00: rank \#131

2026\-10\-01T15:00:51\.048047\+00:00: rank \#132

2026\-10\-01T16:00:53\.034654\+00:00: rank \#133

2026\-10\-01T16:36:37\.180071\+00:00: rank \#134

2026\-10\-01T17:00:23\.382263\+00:00: rank \#134

2026\-10\-01T18:01:44\.046011\+00:00: rank \#135

2026\-10\-01T19:01:47\.420738\+00:00: rank \#136

2026\-10\-01T20:01:39\.585083\+00:00: rank \#136

2026\-10\-01T21:01:45\.872085\+00:00: rank \#137

2026\-10\-01T22:01:37\.214899\+00:00: rank \#136

2026\-10\-01T23:04:11\.395288\+00:00: rank \#139

2026\-10\-02T08:02:26\.819307\+00:00: rank \#140

2026\-10\-02T09:02:51\.51649\+00:00: rank \#142

2026\-10\-02T10:02:12\.346099\+00:00: rank \#143

2026\-10\-02T11:02:22\.794376\+00:00: rank \#143

2026\-10\-02T12:01:14\.681578\+00:00: rank \#143

2026\-10\-02T13:02:29\.511591\+00:00: rank \#143

2026\-10\-02T14:01:40\.936738\+00:00: rank \#143

2026\-10\-02T15:02:30\.225476\+00:00: rank \#144

2026\-10\-02T16:02:47\.060695\+00:00: rank \#144

2026\-10\-02T17:02:31\.351493\+00:00: rank \#146

2026\-10\-02T18:01:22\.271899\+00:00: rank \#147

2026\-10\-02T19:01:23\.681417\+00:00: rank \#148

2026\-10\-02T20:01:33\.801055\+00:00: rank \#150

2026\-10\-02T21:02:55\.453316\+00:00: rank \#153

2026\-10\-02T22:01:50\.233139\+00:00: rank \#154

2026\-10\-02T23:01:20\.268516\+00:00: rank \#152

2026\-10\-03T08:01:30\.186188\+00:00: rank \#154

2026\-10\-03T09:01:57\.91467\+00:00: rank \#154

2026\-10\-03T10:00:55\.732001\+00:00: rank \#153

2026\-10\-03T11:01:22\.538596\+00:00: rank \#153

2026\-10\-03T12:01:08\.789384\+00:00: rank \#154

2026\-10\-03T13:00:35\.273559\+00:00: rank \#154

2026\-10\-03T14:00:48\.425606\+00:00: rank \#154

2026\-10\-03T15:01:04\.472963\+00:00: rank \#154

2026\-10\-03T16:01:56\.56175\+00:00: rank \#155

2026\-10\-03T17:01:36\.651036\+00:00: rank \#153

2026\-10\-03T18:01:58\.24207\+00:00: rank \#153

2026\-10\-03T19:01:19\.196589\+00:00: rank \#153

2026\-10\-03T20:00:57\.313759\+00:00: rank \#153

2026\-10\-03T21:01:04\.44439\+00:00: rank \#153

2026\-10\-03T21:20:01\.585706\+00:00: rank \#153

2026\-10\-03T22:00:15\.503126\+00:00: rank \#153

2026\-10\-03T23:00:55\.584832\+00:00: rank \#153

2026\-10\-04T08:01:00\.327459\+00:00: rank \#153

2026\-10\-04T09:00:59\.321023\+00:00: rank \#154

2026\-10\-04T10:00:42\.975336\+00:00: rank \#154

2026\-10\-04T11:01:03\.76577\+00:00: rank \#154

2026\-10\-04T12:01:45\.307985\+00:00: rank \#155

2026\-10\-04T13:00:49\.176267\+00:00: rank \#155

2026\-10\-04T14:00:56\.952543\+00:00: rank \#155

2026\-10\-04T15:00:54\.739637\+00:00: rank \#156

2026\-10\-04T16:00:51\.403054\+00:00: rank \#157

2026\-10\-04T17:00:43\.166713\+00:00: rank \#157

2026\-10\-04T18:00:46\.315535\+00:00: rank \#156

2026\-10\-04T19:00:54\.768841\+00:00: rank \#156

2026\-10\-04T20:00:51\.070442\+00:00: rank \#157

2026\-10\-04T21:00:28\.550532\+00:00: rank \#156

2026\-10\-04T22:01:36\.217651\+00:00: rank \#158

2026\-10\-04T23:01:09\.400767\+00:00: rank \#159

2026\-10\-05T08:01:51\.387003\+00:00: rank \#159

2026\-10\-05T09:01:40\.528475\+00:00: rank \#159

2026\-10\-05T10:00:56\.290772\+00:00: rank \#159

2026\-10\-05T11:01:05\.919518\+00:00: rank \#159

2026\-10\-05T12:00:56\.590881\+00:00: rank \#159

2026\-10\-05T13:01:05\.197156\+00:00: rank \#161

2026\-10\-05T14:01:04\.085718\+00:00: rank \#161

2026\-10\-05T15:00:50\.814571\+00:00: rank \#161

2026\-10\-05T16:02:09\.54139\+00:00: rank \#161

2026\-10\-05T17:00:35\.336076\+00:00: rank \#161

2026\-10\-05T18:00:20\.445491\+00:00: rank \#161

2026\-10\-05T19:02:43\.604975\+00:00: rank \#162

2026\-10\-05T20:01:09\.777459\+00:00: rank \#162

2026\-10\-05T21:01:47\.650671\+00:00: rank \#163

2026\-10\-05T22:02:59\.93099\+00:00: rank \#164

2026\-10\-06T08:02:11\.210914\+00:00: rank \#164

2026\-10\-06T08:02:14\.354697\+00:00: rank \#164

2026\-10\-06T09:01:21\.688765\+00:00: rank \#166

2026\-10\-06T10:00:58\.047773\+00:00: rank \#166

2026\-10\-06T11:00:41\.689929\+00:00: rank \#167

2026\-10\-06T12:00:41\.7705\+00:00: rank \#168

2026\-10\-06T13:01:24\.509519\+00:00: rank \#168

2026\-10\-06T14:00:26\.950817\+00:00: rank \#168

2026\-10\-06T15:00:49\.066414\+00:00: rank \#170

2026\-10\-06T16:00:58\.166747\+00:00: rank \#172

2026\-10\-06T17:01:17\.009511\+00:00: rank \#172

2026\-10\-06T18:01:43\.791429\+00:00: rank \#173

2026\-10\-06T19:00:46\.048609\+00:00: rank \#173

2026\-10\-06T20:01:14\.687294\+00:00: rank \#174

2026\-10\-06T21:02:13\.414382\+00:00: rank \#174

2026\-10\-06T22:00:40\.926271\+00:00: rank \#173

2026\-10\-06T23:03:26\.867445\+00:00: rank \#175

2026\-10\-07T08:01:41\.339804\+00:00: rank \#176

2026\-10\-07T09:02:38\.026986\+00:00: rank \#178

2026\-10\-07T10:01:35\.069531\+00:00: rank \#178

2026\-10\-07T11:02:07\.770084\+00:00: rank \#178

2026\-10\-07T12:01:14\.996697\+00:00: rank \#177

2026\-10\-07T13:00:47\.45912\+00:00: rank \#176

2026\-10\-07T14:01:18\.307739\+00:00: rank \#176

2026\-10\-07T15:01:57\.541362\+00:00: rank \#179

2026\-10\-07T16:01:28\.474022\+00:00: rank \#179

2026\-10\-07T17:01:15\.036908\+00:00: rank \#180

2026\-10\-07T18:00:53\.300079\+00:00: rank \#180

2026\-10\-07T19:01:49\.456657\+00:00: rank \#181

2026\-10\-07T20:01:59\.032487\+00:00: rank \#181

2026\-10\-07T21:05:36\.655392\+00:00: rank \#183

2026\-10\-07T22:02:27\.105241\+00:00: rank \#184

2026\-10\-07T23:01:17\.452894\+00:00: rank \#184

2026\-10\-08T08:03:55\.083808\+00:00: rank \#184

2026\-10\-08T09:03:58\.68898\+00:00: rank \#184

2026\-10\-08T10:04:05\.364235\+00:00: rank \#185

2026\-10\-08T11:02:04\.410307\+00:00: rank \#184

2026\-10\-08T12:02:36\.39618\+00:00: rank \#184

2026\-10\-08T13:03:09\.206401\+00:00: rank \#184

2026\-10\-08T14:03:30\.113384\+00:00: rank \#185

2026\-10\-08T15:02:54\.444758\+00:00: rank \#183

2026\-10\-08T16:03:13\.067807\+00:00: rank \#182

2026\-10\-08T17:03:47\.92465\+00:00: rank \#181

2026\-10\-08T18:01:50\.360431\+00:00: rank \#181

2026\-10\-08T19:02:55\.719274\+00:00: rank \#182

2026\-10\-08T20:01:36\.359022\+00:00: rank \#182

2026\-10\-08T21:03:34\.000719\+00:00: rank \#184

2026\-10\-08T22:01:13\.459732\+00:00: rank \#184

2026\-10\-08T23:01:25\.318392\+00:00: rank \#183

2026\-10\-09T08:01:53\.314021\+00:00: rank \#184

2026\-10\-09T09:02:59\.93426\+00:00: rank \#185

2026\-10\-09T10:02:22\.652527\+00:00: rank \#185

2026\-10\-09T11:02:04\.807282\+00:00: rank \#185

2026\-10\-09T12:02:16\.769295\+00:00: rank \#185

2026\-10\-09T13:02:30\.35034\+00:00: rank \#187

2026\-10\-09T14:01:34\.215134\+00:00: rank \#187

2026\-10\-09T15:01:27\.564392\+00:00: rank \#187

2026\-10\-09T16:02:06\.561056\+00:00: rank \#188

2026\-10\-09T17:03:06\.673648\+00:00: rank \#190

2026\-10\-09T18:01:02\.851052\+00:00: rank \#190

2026\-10\-09T19:01:11\.250291\+00:00: rank \#191

2026\-10\-09T20:01:32\.91907\+00:00: rank \#191

2026\-10\-09T21:02:08\.376144\+00:00: rank \#193

2026\-10\-09T22:01:19\.253075\+00:00: rank \#195

2026\-10\-09T23:01:31\.990912\+00:00: rank \#195

2026\-10\-10T08:01:00\.593376\+00:00: rank \#194

2026\-10\-10T09:01:45\.527975\+00:00: rank \#197

2026\-10\-10T10:00:53\.799353\+00:00: rank \#197

2026\-10\-10T11:00:35\.65851\+00:00: rank \#196

2026\-10\-10T12:01:11\.169647\+00:00: rank \#196

2026\-10\-10T13:00:54\.008377\+00:00: rank \#196

2026\-10\-10T14:01:43\.208766\+00:00: rank \#198

2026\-10\-10T15:01:24\.825188\+00:00: rank \#198

2026\-10\-10T16:01:10\.213328\+00:00: rank \#197

2026\-10\-10T17:00:48\.84189\+00:00: rank \#196

2026\-10\-10T18:00:57\.55132\+00:00: rank \#196

2026\-10\-10T19:00:52\.379463\+00:00: rank \#195

2026\-10\-10T20:00:21\.993912\+00:00: rank \#195

2026\-10\-10T21:01:10\.657738\+00:00: rank \#197

2026\-10\-10T22:00:50\.433569\+00:00: rank \#196

2026\-10\-10T23:01:00\.95027\+00:00: rank \#197

CrowdSec's statement frames the leak as limited and likely caused by a Tanstack CI/CD compromise, while the discussion centers on operational false positives, packaging and SaaS dependencies, and whether an IP\-reputation service should be governed differently\.

## The brief

CrowdSec says it confirmed a May 2026 GitHub source\-code leak after being notified on September 16\. The private repositories included SaaS console code, AWS Cloud routines, connectors, and automations, while the public FOSS Security Engine is out of scope\. CrowdSec says the 300\-repository figure includes 130\+ public repos and mostly reflects code subdivision, that no client data, PII, logs, or credentials were found leaked so far, and that the likely vector was the Tanstack compromise, which backdoored a component to extract a CI/CD API key with private\-codebase read access\. CrowdSec says it rotated tokens and credentials and is monitoring for abnormal activity\.

- CrowdSec confirmed a source\-code leak involving its GitHub repository after a September 16 report; the leak occurred in May 2026\.
- The private code included the SaaS console, some AWS Cloud routines, connectors, and automations; the public FOSS Security Engine was out of scope\.
- CrowdSec says the 300\-repository headline is accurate when including 130\+ public repos, but mostly reflects how the code is subdivided\.
- CrowdSec says no client data, login/password, name, organization, PII, or client logs were leaked, and no token or credential enabling lateral movement was found so far\.
- CrowdSec attributes the likely leak vector to the Tanstack compromise, which backdoored a component to extract a CI/CD API key authorized to read the private codebase\.
- CrowdSec says it rotated required tokens and credentials, argues the leaked code cannot easily replicate its network effect, and will monitor for abnormal activity\.

## Discussion themes

### Governance and security\-company framing

Commenters debated whether CrowdSec qualifies as a security company and whether IP\-reputation data should be run by a trusted nonprofit\. One commenter calls it an aggregator of bad IPs and proposes a trusted not\-for\-profit with nominal query fees; another challenges that model, asking how nominal fees would pay engineers and infrastructure; a reply defines a security company by whether security practices directly affect revenue and cites Let's Encrypt as a nonprofit alternative\.

Sources: [Comment 49743105](<https://news.ycombinator.com/item?id=49743105>) · [Comment 49743380](<https://news.ycombinator.com/item?id=49743380>) · [Comment 49743538](<https://news.ycombinator.com/item?id=49743538>)

### False positives in production

A user reported unacceptable false positives when using CrowdSec for bot/scraping mitigation: they say the architecture was sound but they turned it off after a couple of days following months of preparation\. Another commenter adds that legitimate users were blocked, possibly including VPN exit nodes, CG\-NAT users, or shared networks with compromised devices, generating support requests\.

Sources: [Comment 49743364](<https://news.ycombinator.com/item?id=49743364>) · [Comment 49744241](<https://news.ycombinator.com/item?id=49744241>)

### Counterpoint on false positives and tuning

Another commenter disputes the false\-positive characterization, saying CrowdSec's blacklists did not seem false\-positive\-prone, that users choose and fine\-tune rulesets, and that they use the free version as a simple WAF on multiple servers with initial tuning\. They ask for better open\-source alternatives\.

Sources: [Comment 49743665](<https://news.ycombinator.com/item?id=49743665>)

### Packaging and SaaS dependency

A commenter says their Debian 13 VPS stopped receiving the community blocklist because they ran the old Debian\-packaged version rather than CrowdSec's direct version, returning HTTP 500\. They used an LLM to build a blocklist from public sources instead of tying themselves more tightly to CrowdSec's SaaS platform\.

Sources: [Comment 49744063](<https://news.ycombinator.com/item?id=49744063>)

### Leak visibility and self\-hosting

On the leak itself, a commenter notes CrowdSec likely lacked GitHub traffic visibility and might have had more luck if it had self\-hosted its repositories\.

Sources: [Comment 49743508](<https://news.ycombinator.com/item?id=49743508>)

## Sources & coverage

AI-generated summary · 2026\-09\-18T17:11:59\.539453\+00:00

Based on 9 of 9 usable stored comments, selected by depth and branch activity. This is a sample of the discussion. Article text may also be shortened.

Generated using deepseek\-ai/DeepSeek\-V4\.1\-Flash. Check the linked sources for full context.
