The fall of YGG: hack, 6.6 million accounts and torrent risks
The YGG hack of March 2026: an open Sphinx port, 6.6 million accounts exfiltrated, 36 front websites and laundering through Tornado Cash. Autopsy and lessons.

The fall of YGG (YggTorrent): hack, 6.6 million account leak and the real risks of illegal torrenting
The fall of YGG, formerly YggTorrent, will remain the most significant event in the history of French-speaking peer-to-peer. On the night of 3 to 4 March 2026, the largest French torrent tracker was compromised, its data destroyed and all of its technical and financial backstage exposed: source code, a database of 6.6 million users, financial flows and laundering methods.
Who can claim never to have downloaded anything illegally? Direct download sites, streaming, peer-to-peer platforms: we have all done it. The most active may have received a letter from Hadopi, then from Arcom, rarely taken seriously. Yet the YGG hack demonstrates that far more worrying threats weigh on the users of these services, and torrent users in particular.
This article offers a complete autopsy of the fall of YGG: the tracker’s history, its mercantile drift, the technical flaw exploited, the financial empire and the laundering, the surveillance of users, and then the concrete risks illegal torrenting poses to your anonymity, your banking data and your security.
- YggTorrent is born in June 2017 after the shutdown of T411 and reaches more than 6 million members in 2024.
- Night of 3 to 4 March 2026: compromise by the actor Gr0lum, data destruction and complete exfiltration. Permanent shutdown announced on 4 March.
- Flaw: a Sphinx port (9306) reachable from the Internet with no authentication, no zero-day and no social engineering.
- Finances: 5 to 8.5 million euros generated, 36 front websites, the “CardsShield” plugin, mixing through Tornado Cash.
- Surveillance: a hidden script scanned visitors’ MetaMask and Phantom wallets.
- Lesson: illusory anonymity, credit card theft, data leaks. Everything to lose.
What is YGG (YggTorrent)?
June 2017. After T411 was shut down by the authorities, a huge void was left for millions of French-speaking users. YggTorrent, later renamed Ygg, established itself as a commercial entity of unprecedented scale in the French-speaking peer-to-peer landscape:
- up to more than 6 million members recorded during 2024;
- the 35th most visited website in France on 1 January 2020;
- a constant fight against censorship, one new domain name after another.
A private tracker such as YGG does not store files: it indexes torrents, connects members who share (“seeders”) with those who download, and enforces ratio rules to encourage sharing. It is this community model that would gradually be betrayed.
Timeline of the fall of YGG
Nine years after its launch, one event would precipitate the end of this empire. On the night of 3 to 4 March 2026, the platform is compromised by the actor known as Gr0lum. The breaking point is definitive, not only through the destruction of the data, but above all through the exfiltration of an unprecedented dossier revealing the technical and financial backstage of the organisation.
Everything is out: the source code, the databases and their 6.6 million users, the financial secrets. The permanent shutdown is announced on 4 March. The administrators can no longer deny the breach.
The mercantile drift: the breaking point
The “Turbo” subscription, launched in December 2025 at 14.99 euros per month, marks the financial turning point. Upload credits for sale, ratio rules removed, fewer restrictions: the ideal of free sharing is officially dead, and the tracker no longer has anything to do with the P2P mindset.
The exfiltrated dossier reveals other practices:
- Hard-coded technical discrimination: the API (Express.js) targeted user IDs above 1,000,000, that is, recent sign-ups, with a limit of 5 downloads per day and a 30-second timer before the link is displayed.
- The elite spared: “Staff” ranks (1, 2, 3) were fully exempt from these restrictions.
A class structure that broke the very ideology of P2P. The last straw, and probably one of the attacker’s motivations.
Technical autopsy: the port 9306 hack
The hack turns out to be surprisingly simple compared to the fortress image one might have. It succeeded thanks to an accumulation of bad security practices: no social engineering, no zero-day, just a huge door left open.
Sphinx is a powerful search engine, used by YGG to index more than 280,000 torrents. It talks to MySQL on a very specific port, 9306, through the SphinxQL protocol. This port was public, reachable by anyone from the Internet, with no authentication.
- Network scan: port 9306 (Sphinx) answers from the Internet.
- SphinxQL, the open door: no authentication, the attacker talks freely to the engine.
- File reading: a read function allows extracting the file containing the database credentials, the configuration files describing the infrastructure, and the API keys of the payment services.
- Access to all 6.6 million accounts, then destruction.
The password tally is worrying too: millions of hashes in SHA-512, but also a portion in unsalted MD5, an obsolete format vulnerable to dictionary attacks. A service exposed without authentication is exactly the kind of asset an external penetration test or continuous attack surface monitoring detects in minutes.
The financial empire and money laundering
The turnover is colossal: between 5 and 8.5 million euros generated over the lifetime of the site. To hide these flows, a genuine laundering infrastructure had been set up:
- Fictitious e-commerce: an architecture of 36 “front” websites to collect card payments through PayPal and Stripe without getting banned.
- The “CardsShield” plugin: on their bank statement, the customer saw the name of a “legitimate” company, not YGG.
Once collected, the money was converted into cryptocurrency to limit traceability. But the blockchain keeps traces, hence the use of a common pot and mixing through Tornado Cash, to sever the links between payments and the administrators’ wallets. Irrefutable proof: Tornado Cash deposit notes were found on the pre-production servers of the administrator “Destroy”. The funds were then used for operational expenses, servers and domain names.
User surveillance and the backstage of power
YGG had set up a system to monitor its visitors’ crypto wallets: a sci.js script on the front website, hidden under the name ImageCarouselManager. It scanned the browser for MetaMask or Phantom wallets, then exfiltrated the IP address and the wallet type into a divers/web3_stats folder. Goal: profile users for phishing, or adapt prices to the person. Total contempt for members’ privacy.
The org chart is clearly identifiable:
- Oracle: the technical brain, invisible and disconnected from the staff.
- YggFlop (Vlad): the executor, handling money, recruitment and technical directives through Telegram.
The platform’s paradox lies in the exploitation of volunteers: five moderators (including Bar666 and Macha64) carried out 73% of the work, 1.3 million actions, without receiving a cent of the profits. And anyone asking too many questions was excluded.
The real risks of illegal torrenting for users
Why is the YGG hack an excellent reason to stop using shady P2P platforms?
- Anonymity is an illusion. The leak shows that most of the staff were not careful: no VPN, all located in France through providers such as Free and Orange. Members, for their part, sit in a database of 6.6 million accounts with emails and IP addresses. Only Oracle, the administrator, kept perfect opsec, 100% VPN, which prevents confirming his presumed location in Morocco.
- Your banking data passes through unknown hands. The suspicions of card theft and the fraud testimonies attest to it.
- You are being profiled. The wallet detection script shows that the administrators did not hesitate to spy on their own members.
- Your data ends up on the dark web. Emails, weakly hashed passwords and download histories become ammunition for phishing and identity theft.
In short, everything to lose.
What future for YGG?
The future looks compromised. The administrators responded by trying to dox Gr0lum, unconvincingly. The authorities will take care of the rest, and there is no plan to bring the platform back.
Frequently asked questions about the YGG hack
Is YGG permanently closed?
Yes. The permanent shutdown was announced on 4 March 2026, the day after the compromise. The administrators have no plan to bring the platform back.
Is my data in the YGG leak?
If you had a YggTorrent or YGG account, your information (email, hashed password, IP address, history) is part of the 6.6 million exfiltrated records. Immediately change any password reused elsewhere and enable two-factor authentication on your sensitive accounts.
How was YGG hacked?
Through a Sphinx port (9306) exposed to the Internet with no authentication. The attacker was able to read configuration files, retrieve database credentials and payment API keys, then access every account.
Is a VPN enough to torrent safely?
A VPN hides your IP address from other peers, but protects neither your account data stored by the platform, nor your credit card, nor your browser against profiling scripts. The YGG hack shows that the main risk comes from the platform itself.
Key takeaways
The fall of YGG is not only the end of a download site. It is the demonstration that an illegal platform, by nature, meets no security or data protection obligation: its users are both its resource and its victims. To understand how this kind of exposure is detected, discover our approach to continuous attack surface monitoring.
Sources
- YggLeak, The Ygg dossier
- YggLeak, About