Funnull purchased the polyfill.io domain in July 2024
Assessment
The date is impossible on the incident's own timeline. Malicious behaviour from the domain was identified on 24 June 2024, Sansec published its analysis on 25 June, and Namecheap suspended the domain on 27 June — all before July 2024. The domain cannot have been acquired after the attack it enabled had already been stopped. The February 2024 date is established from several independent directions. Sansec's report states "In February this year, a Chinese company bought the domain and the Github account." Andrew Betts, the library's original author, published a warning to remove the dependency on 25 February 2024, explaining he had never owned the domain and had no influence over its sale. Cloudflare and Fastly launched replacement mirrors on 29 February 2024. None of those three responses is possible before the acquisition that prompted them. This is recorded despite the source being an unusually reliable one, and that is the reason it is worth recording: a date error in a well-regarded outlet propagates further than the same error elsewhere, precisely because readers do not expect to have to check it.
Where this claim appeared
Krebs on Security · 2025-07-26
https://krebsonsecurity.com/2025/07/big-techs-mixed-response-to-u-s-treasury-sanctions/What “False” means
Contradicted by primary sources. Reserved for claims checked directly against the authoritative record — an advisory that does not exist, a catalogue that does not list the entry, a directive that says something other than what is reported.
1 of 5 · rating scale
Assessed in
Polyfill.io: How a CDN Acquisition Backdoored Hundreds of Thousands of SitesThink this assessment is wrong? Report an error.