Leaked consensus thresholds don't let attackers poison CrowdSec's blocklist
Assessment
The most security-relevant content of the leak is CrowdSec's blocklist consensus algorithm and, for the first time publicly, the thresholds it uses to decide when an IP address is added to the blocklists distributed to CrowdSec's ~150,000 users. CrowdSec assesses that the blocklist still cannot be poisoned (tricked into blocking a harmless IP) even with those thresholds exposed, arguing an attacker would need tens of detections from tens of trusted engines across tens of separate networks at great cost, and that it can change the thresholds. This is a reasoned first-party assessment, explicitly qualified as true 'as far as it knows' — not an independently verified guarantee. Whether knowledge of the thresholds yields any practical evasion or poisoning capability over time is exactly the sort of thing a determined adversary, not the vendor, ultimately tests.
Where this claim appeared
CrowdSec (via The Hacker News) · 2026-09-19
https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.htmlWhat “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
CrowdSec source-code leak: how the breach account changed in 24 hours, from 'no personal data' to 83 usersThink this assessment is wrong? Report an error.