EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/twitch-source-code-leak-2021
174/430

File EL-0257HighResolvedData Breach / Source Code and Financial Data Exfiltration

Twitch Source Code and Creator Revenue Leak

Also filed as Twitch Repository Dump · Twitch Payout Data Leak

This incident involved the public release of a massive data dump containing the full source code repositories for Twitch's web and mobile clients. Crucially, the leak also exposed internal financial records detailing creator payout amounts for several years.

  • #twitch
  • #source-code
  • #data-leak
  • #creator-economy
  • #amazon
  • #streaming
  • #financial-data
Notoriety7/10
Event
6 Oct 2021
Disclosed
6 Oct 2021
Target
Twitch.tv
Actor
Anonymous (4chan)
Scale
Multiple repositories and financial records
Status
Resolved

01Summary

On October 6, 2021, an anonymous source posted a comprehensive dump claiming to contain Twitch.tv's entire repository. The leak included the full frontend source code for `twitch-web` and mobile clients, alongside unreleased code for a competitor platform, `vapor`. Most significantly, the dump contained detailed financial records spanning 2019 to 2021, listing the gross payouts for top creators, including figures for CriticalRole, xQcOW, and summit1g. The leak also included internal 'Red Team' security audit tools, providing insight into Twitch's own vulnerability testing methods. The motivation was explicitly stated as fostering disruption and competition within the streaming space.

02Background

Twitch.tv, owned by Amazon, has grown into a dominant platform for live streaming, creating a massive creator economy. The platform's business model relies heavily on the visibility and financial success of its top streamers. This leak targeted the core infrastructure and the financial backbone of this economy.

03Key revelations

  1. 01The full source code for Twitch's web and mobile platforms was exposed, aiding potential competitors or malicious actors.
  2. 02Detailed, multi-year financial records of top creators were leaked, exposing the exact revenue streams and payout structures.
  3. 03Internal security audit tools ('Red Team' tools) were released, providing a blueprint of Twitch's own security testing methodologies.

04Technical analysis

The leak provided access to multiple repositories, including frontend and mobile client source code, allowing for potential reverse engineering and identification of API endpoints. The inclusion of internal security audit tools was particularly valuable, as it revealed the methods and blind spots of Twitch's own security team.

Attack vector
Unknown (Likely internal network compromise or unauthorized repository access)
Attack method
Exfiltration and Public Disclosure
Exfiltration
Unauthorized download/dumping of source code and databases
Malware type
Data Dump/Exfiltration

MITRE ATT&CK techniques

  • T1595.002

05Threat actor

Anonymous, in this context, refers to an unidentifiable collective operating through imageboards like 4chan. Their operations are characterized by decentralized, high-impact, and often politically or socially motivated disclosures, rather than sustained, targeted cyber warfare.

Aliases

  • Anonymous

MITRE groups

  • T1595.002

Attribution sources

  • Public Leak Source

06Victims and impact

Additional victims

  • Amazon

Countries affected

  • United States

07Data exposed

Data types

  • Source Code
  • Financial Records
  • Credentials
  • PII (Creator Names)

Notable documents

  • git/twitch-web source code
  • git/twitch-mobile source code
  • Creator Payouts (2019-2021) database

08Financial damage

Damage is primarily reputational and competitive, rather than immediate financial loss.

09Timeline

  1. 2021-10-06Anonymous posts the comprehensive dump of Twitch source code and financial data.

10Key figures

  • CriticalRoleTop Streamer · TwitchExposed high earning potential on the platform
  • xQcOWTop Streamer · TwitchExposed high earning potential on the platform

11On the record

Their community is a disgusting toxic cesspool, so to foster more disruption and competition in the online video streaming space, we have completely pwned them.

Anonymous, Manifesto accompanying the leak, stating the motive for disruption.

12Reaction and fallout

Public reaction

The public reaction was mixed, ranging from shock at the depth of the data to general indifference, as the leak primarily targeted corporate infrastructure rather than individual PII.

Political impact

The leak intensified the existing debate regarding the economic structure of the creator economy, prompting discussions about platform accountability and creator rights.

13Legal

No immediate legal action was publicly reported against the anonymous leaker, though the leak triggered internal security reviews for Twitch.

14Aftermath

Policy changes

  • Increased scrutiny on platform data handling and source code security practices within the streaming industry.

Security improvements

  • Enhanced internal access controls and source code repository segmentation for major tech platforms.

15Significance and legacy

Significance

This incident is significant because it demonstrated the vulnerability of major tech platforms' core intellectual property (source code) and their most sensitive business data (creator financials). It highlighted the immense value of both proprietary code and the data generated by the creator economy.

Legacy

The leak contributed to a heightened awareness among tech companies regarding the need for robust internal data segregation and the risks associated with centralized, highly valuable source code repositories. It also fueled ongoing discussions about the transparency of platform revenue sharing.

16Disclosure and media

Whistleblower
Anonymous
Authentication
Unverified dump (Source claimed authenticity)

Media partners

  • The Verge
  • TechCrunch
  • Reddit

Publishing organisations

  • 4chan

17Field notes

  1. 01The leak included unreleased code for 'vapor,' a competitor platform, suggesting the dump came from a highly privileged internal source.
  2. 02The financial data provided specific gross payout figures, which are highly sensitive business metrics.

18Resolution

Twitch did not issue a detailed public statement regarding the full scope of the breach, but the incident prompted internal security reviews and discussions about data governance.

19Sources

References

  1. [1]4chan posts
  2. [2]Tech news reports (2021)
Fact sheetEL-0257

Dates

Event
6 Oct 2021
Discovered
6 Oct 2021
Disclosed
6 Oct 2021
Ongoing
No

Target

Organisation
Twitch Interactive, LLC
Type
Technology Company
Sector
Online Video Streaming
Country
United States

Actor

Name
Anonymous (4chan)
Type
Hacktivist Group
Motivation
Disruption, exposing corporate practices, and criticizing the streaming platform's community culture.
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

Volume
Multiple repositories and financial records
Sensitivity
Secret
Published
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.