Endchan Hacked
Yesterday (2026 February 11) users exploited a bug in the engine and escalated privileges on user accounts. They gained "root" access to the site, getting the highest privilege, which means they could see user's IPs of all the posts, change site settings, lifting range bans, delete threads and posts.
The real problem from the above is the IPs, which could help breaking anonymity of the users.
It seems they had no access to the database so for example they couldn't get to email addresses of registered users. Other than these two types of data, there is not much else to gain.
We found and patched the bug. We are still auditing the logs and the engine, if new information emerges, we'll share it.
Maybe this event means a hit for the site's reputation, but now we can tell that we are on the same level as 4chan. Though at least it is still not 4chan.
No role signo competence is showing.