ThreatPaper
Assessed, Not Confirmed

Leaked consensus thresholds don't let attackers poison CrowdSec's blocklist

Assessment

The most security-relevant content of the leak is CrowdSec's blocklist consensus algorithm and, for the first time publicly, the thresholds it uses to decide when an IP address is added to the blocklists distributed to CrowdSec's ~150,000 users. CrowdSec assesses that the blocklist still cannot be poisoned (tricked into blocking a harmless IP) even with those thresholds exposed, arguing an attacker would need tens of detections from tens of trusted engines across tens of separate networks at great cost, and that it can change the thresholds. This is a reasoned first-party assessment, explicitly qualified as true 'as far as it knows' — not an independently verified guarantee. Whether knowledge of the thresholds yields any practical evasion or poisoning capability over time is exactly the sort of thing a determined adversary, not the vendor, ultimately tests.

Where this claim appeared

CrowdSec (via The Hacker News) · 2026-09-19

https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

CrowdSec source-code leak: how the breach account changed in 24 hours, from 'no personal data' to 83 users

Think this assessment is wrong? Report an error.