Addressing What Happened Back in June

Published on October 7, 2025

Recently, developers noClaps, InsidiousFiddler and RollViral discovered several security vulnerabilities in our services and reached out to us.

First, let us say that we are extremely grateful that these individuals reported the issues to us. While we acknowledged some of the issues they identified, we regret that we left them unresolved for too long. This was very unprofessional on our part, and the fact that these vulnerabilities existed is entirely our fault, so we take full responsibility for these oversights.

Issues Identified

The reports highlighted several technical gaps. In summary:

These issues exposed missing checks that conflicted with our expectation of "no shortcuts" in security.

Our Response

One of our developers was contacted via Discord by the individual who discovered the first issue on June 23, 2025. A group chat was created including all three individuals reporting the vulnerabilities, one Secton developer, and one QA team member.

We were able to reproduce all the reported issues and prioritized patches for them. By the next day (June 24, 2025), all identified issues had been resolved and deployed to production. Importantly, there is no evidence that any of these vulnerabilities were abused in the wild; these issues were only exposed through the individuals' responsible testing.

One of the individuals who reported these issues shared their perspective on our team:

I truly don't know if their code was AI-generated or if their developers are juniors who are still learning, though I don't believe I have the true right to judge that. However, I do hope that at least they took this with a stride and learn from it.

Admittedly, we do use AI-assisted development tools internally (as many teams do), however all production code is carefully reviewed by multiple engineers.

Once again, we take full responsibility for leaving these issues unresolved initially and sincerely regret that they existed at all. We appreciate the responsible disclosure and the time the individuals took to work with us directly.

Improvements Made


We want to thank the community for their vigilance. If you have questions about any of the issues mentioned above (or if you spot something we missed) please reach out on Discord or via email. Your trust is paramount, and we're doubling down on keeping your data (as well as our services) safe.

— The Secton Team