Capsuleers.app logo CAPSULEERS.APP
Banner

EVE Online Security Update - 8 September, 2026

EVE Online Team
Archive Data Feed

Capsuleers,

On Friday, we became aware of some odd behavior: players were receiving donations of 0 ISK. Given how quickly these were being sent out, and how many were affected, it was clear that automation was at play. We banned the characters involved and kept digging.

During that investigation, we discovered a client vulnerability that allowed a player using a modified client to send a donation and, in return, see the recipient’s wallet balance. We also confirmed that this vulnerability was unrelated to the recent Python changes.

As of today’s downtime, that vulnerability has now been fixed.

The player used four accounts to send approximately one million separate donations over six hours on Friday 4 September, collecting a snapshot of character and corporation wallet balances.

The exposed information was limited to character and corporation ISK wallet balances at the time of the donations. For corporations, this affected the master wallet and not any of the other divisions. PLEX balances were not exposed, and no other wallet data, like transfers or transaction history, was exposed. Critically, no personal information, such as account usernames or email addresses, was exposed.

Today’s fix prevents further use of the exploit, but it’s very likely that this information with wallet balance snapshots is already circulating.

To check whether you were affected, look in your wallet journal for an incoming donation of 0 ISK on Friday 4 September between 15:00 and 21:00 UTC from any of these characters:

  • Mye Esubria

  • fxprobe1

  • fenriscw1

  • Skiasten

The intent behind this activity is unclear, so although no username or account names were discovered by this exploit we still strongly encourage all players to enable two-factor authentication (2FA) as a general account security measure. It wouldn’t have prevented this exposure, but it adds another layer of protection to your account. As always, please report any unusual activity on your account to EVE Online Support.

Thank you for your vigilance and for reporting concerns to us.

FAQ & TL;DR

Was my character affected?

Given the number of donations sent, it's very likely that this occurred. To confirm, look in your wallet journal for an incoming donation of 0 ISK on Friday 4 September between 15:00 and 21:00 UTC from any of these characters: fenriscw1, Mye Esubria, fxprobe1, Skiasten

What information was shared?

The vulnerability allowed the donator to get a snapshot of your wallet balance at the moment of donation. For corporations, this involved the balance in the master wallet. No information about transactions, PLEX balance, marker orders, bills, of assets.

Is my account in danger?

No account information, like usernames, email addresses, or billing information was exposed. However, we strongly encourage players to enable two-factor authentication (2FA) as a general account security measure.

Am I still affected?

The character wallet balance was shared at the moment of the donation, and it does not update after that. With the vulnerability now fixed, future donations from a modified client will not "refresh" the wallet balance.

Original source:eveonline.com— Read the original