That's All Folks: Versus Market is Retiring
In a post on May 18, 2022, AlphaBay administrator DeSnake published an announcement on Dread about “security issues on Versus.” DeSnake then worked with the Dread user /u/threesixty to verify the existence of the vulnerability discovered by the hacker.

WilliamGibson, a Versus staffer, announced the market's shutdown on Dread.
DeSnake’s explained the exploit in his Dread post:
“The exploit is extremely simple but compromising. It allows for full access to the underlining file system on the server. This include information within the /etc/ directory as well as wallet directories. It is a full information compromise of the system. Everything to the server’s IP address, to the backup of the database in the admin home folder, to the wallet files themselves. I am able to traverse nearly the entire file system with web server level access. There is no jail, WAF, and minimal care to limit the information disclosure in the event of a web server compromise. I am able to view the history of IP addresses which have previously accessed the server.”
Paris, the co-administrator of Dread, later verified the exploit’s existence.
The market has been unreachable since DeSnake published the disclosure on Dread, if not earlier (the market’s backend returned a “white screen of death” after some of DeSnake’s testing). On May 22, 2022, Versus Market staff member /u/WilliamGibson announced the market’s permanent retirement. In the announcement, WilliamGibson wrote that Versus Market’s staff spent several days analyzing the severity of the vulnerability.
“After an in-depth assessment, we did identify a vulnerability which allowed read-only access to a 6+ month old copy of the database as well as a potential ip leak of a single server we used for less than 30 days,” WilliamGibson wrote.
The market wanted to contest some of the claims made about the vulnerability. Specifically, WilliamGibson wrote, “there was no server pwn and users/vendors have nothing to worry about as long as standard and basic opsec practices have been utilized (for example, PGP encryption).” Members of the market’s team feel as if a “clear agenda” existed in the way people handled the discovery and disclosure of the vulnerability.

Versus Market is the most popular Western marketplace | Picture: @DarkDotFail
Others on Dread have questioned DeSnake’s involvement in the disclosure, pointing out that AlphaBay inevitably benefits from the demise of any competition. One Dread user asked, “all good intentions aside. Isn’t it an advantage to eliminate your competition and gain more users for your own marketplace?”
DeSnake answered the question, stating, “yes it is and we do not hide that. As I explained in several posts some minutes ago the effect of such a vulnerability is much, much bigger to all marketplaces and the scene as a whole and while we do benefit from it, it is a small if not insignificant compared to what could have actually happened.”
Paris provided a similar answer and suggested that law enforcement had already compromised the server unless they were “sitting on their hands.”
The sentiment of users commenting on posts about the vulnerability appears to be generally balanced. Although many are skeptical of the way the motivations for DeSnake’s disclosure, others thanked the parties involved for “not outright exposing the exploit and/or leaking the database.” (DeSnake claimed that he did “not leak the database or [steal] any coins.” The market recovered from a Bitcoin theft once before when hackers drained Versus’ escrow wallet).

DarkDotFail claims the market had “a troubled history.”
WilliamGibson’s retirement post highlighted the market’s climb to the top.
“We built Versus from scratch and ran for 3 years. We built a community and even became the #1 DNM when we never intended for that to be the goal. At a certain point, there is no further way up to go, only down, and in this business it is best to not make decisions out of pride. While we are not ending on the note that we would have liked, we hope that the truth about the actual scope of the vulnerability, combined with the impact we have had on the community, leaves users remembering Versus fondly for years to come. Versus Market has officially retired and we thank you for your support and being part of something that hopefully defined the future of DNM’s.”
And he closed by thanking the community and telling Versus Market vendors that he will provide a link where they will be able to access their transactions without a locktime.<details id="signed-message-from-williamgibson"><summary class="u__s a2w">Signed Message from WilliamGibson</summary><div class="a2x"><div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl">-----BEGIN PGP SIGNED MESSAGE-----</span></span><span class="line"><span class="cl">Hash: SHA512</span></span><span class="line"><span class="cl"></span></span><span class="line"><span class="cl"></span></span><span class="line"><span class="cl"></span></span><span class="line"><span class="cl">Dear Community,</span></span><span class="line"><span class="cl"></span></span><span class="line"><span class="cl">There is no doubt that there has been a lot of concern and uncertainty regarding Versus in the last few days. Most of you that have come to know us have rightfully assumed that our silence has been spent working behind the scenes to evaluate the reality of the proposed vulnerability. After an in-depth assessment, we did identify a vulnerability which allowed read-only access to a 6+ month old copy of the database as well as a potential ip leak of a single server we used for less than 30 days. We take any and every vulnerability extremely seriously but we do think that its important to contend a number of the claims that were made about us. Specifically of importance: there was no server pwn and users/vendors have nothing to worry about as long as standard and basic opsec practices have been utilized (for example, PGP encryption)</span></span><span class="line"><span class="cl">In many ways, we are glad to see the community coming together to improve everyone's security, this was our dream from the beginning with Versus, though we will say that there was a clear agenda behind the way this was originally handled, but we leave you to draw your own conclusions</span></span><span class="line"><span class="cl">Once we identified the vulnerability, we were posed with a fork in the road, to rebuild and come back stronger (as we had done before) or to gracefully retire. After much consideration, we have decided on the latter. We built Versus from scratch and ran for 3 years. We built a community and even became the #1 DNM when we never intended for that to be the goal. At a certain point, there is no further way up to go, only down, and in this business it is best to not make decisions out of pride. While we are not ending on the note that we would have liked, we hope that the truth about the actual scope of the vulnerability, combined with the impact we have had on the community, leaves users remembering Versus fondly for years to come. Versus Market has officially retired and we thank you for your support and being part of something that hopefully defined the future of DNM's.</span></span><span class="line"><span class="cl"></span></span><span class="line"><span class="cl">For all our vendor:</span></span><span class="line"><span class="cl">We will soon publish a link where you guys can get your transactions without the locktime. No need to wait 90 days.</span></span><span class="line"><span class="cl">It was a good run and I would like to thank you all.</span></span><span class="line"><span class="cl"></span></span><span class="line"><span class="cl">All the best,</span></span><span class="line"><span class="cl">William Gibson</span></span><span class="line"><span class="cl"></span></span><span class="line"><span class="cl">-----BEGIN PGP SIGNATURE-----</span></span><span class="line"><span class="cl"></span></span><span class="line"><span class="cl">iQKTBAEBCgB9FiEEFAl5ki+ljOnGotMlXFDURnuuQqEFAmKKRLJfFIAAAAAALgAo</span></span><span class="line"><span class="cl">aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDE0</span></span><span class="line"><span class="cl">MDk3OTkyMkZBNThDRTlDNkEyRDMyNTVDNTBENDQ2N0JBRTQyQTEACgkQXFDURnuu</span></span><span class="line"><span class="cl">QqHryQ/+IAUfX7anIWAESD5AIPz/gBt9ufFovPHWl13SCDghpgt9v0Zu6zv03WSK</span></span><span class="line"><span class="cl">1e/RlVUTXfAfMdyvlXCMy6ItdtEsQi4dBHzy/exgr9Obrg0NLu4ie1poyp7c3+Vk</span></span><span class="line"><span class="cl">h3Ok6PX2FcCSKMNTZUYa0z7ycHK+NOop+IfG/MErPVRx0eVMvjCQRw3+QMgVm75P</span></span><span class="line"><span class="cl">NqnCh1bdesOReMAbnMrdqTLWTfgIxAXJ4KMhxbawBx1SWg+34wBcHbTjGh/SIlHI</span></span><span class="line"><span class="cl">vTBN6ROt3bxc6M+8JPxAMb9+Ai1h1rcqgYy+T3wW3bkP97eEtbkOI4jKwsUhyiLQ</span></span><span class="line"><span class="cl">Zoq9PNkzRRIiyxzttdBB49tWGUewGKTgnWlmQc4LEcMGK13jAu0uJ2r+wsq24Kl3</span></span><span class="line"><span class="cl">YuQjzkN8bZCLqFyy+Zdu1uJszER1RGSFTk6QtMBtztlNHGX7XpDQXbz+4OXhwCzj</span></span><span class="line"><span class="cl">ag58VyosXNI51LPEuzNlNWszE6r+HuS0Jcjh6ImsMYL6NlhmZ+uz2zWVXO1xL90O</span></span><span class="line"><span class="cl">eTx4Zb3kCWHSppUZJivnEd6I3tvgE1pfkP9y2R9RmcWif9JPsnNwCsc3pzStrPAE</span></span><span class="line"><span class="cl">c26wWvrKeEU5Gr+5PYMY3YDciTSUnER/k8/s9bCUm7v+NkIyJAOb2fNOmL8gSl8e</span></span><span class="line"><span class="cl">pQ0kYSAedfNSiQptiK6lEK+0d5oDy99MTxWGbHNY2Y+akisl/v4=</span></span><span class="line"><span class="cl">=QV1O</span></span><span class="line"><span class="cl">-----END PGP SIGNATURE-----</span></span></code></details>
dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/d492c9d27bceb87fed69
Comments (38)
Nigga Love2022-05-24c0bcbec0
and I’m vewy, vewy sorry for making fun of all the blacks, I would not laugh much without black folks life would be boring ✌🏿
A02kay2022-05-24d0855ae0
This 1z for you DeSnake, whoever you are, if you know what I’m saying, you are a person and the syntax of your sentences would lead me to believe you are a highly educated American male in his 40z. I think we all admire you a little bit, I mean you should be in a Hollywood movie, that you survived AB1.0 and came back not motivated entirely by money, it would seem, I wonder how good of friends you were with A02kay… amazing time to wittiness you do this, I wish you all the best in whatever your endeavors in life may be, it’s far past the streets hahaha do you worry one day they will catch you, amazing courage to say the least…
chimpanzee2022-05-24fd2ec730
Best market I've ever seen! I don't belive the FUD. This so called "obvious" vulnerability been there for 3+ years and nobody noticed? Very unlikely no? More likely paris in desnakes pocket.
TheKingisDread2022-05-24cdc5b920
I think that right now the best option is Bohemia. they are on the SuperList and have all the reputable and established vendors. They also kind of Low Key type which makes them less of a target for hackers and/or Law Enforcement. [url=http://bohemiaobko4cecexkj5xmlaove6yn726dstp5wfw4pojjwp6762paqd.onion/member.php?action=register&ref=B9QXY4G0Cq]Verified link from Bohemia[/url] http://bohemiaobko4cecexkj5xmlaove6yn726dstp5wfw4pojjwp6762paqd.onion/member.php?action=register&ref=B9QXY4G0Cq (This is an affiliate link. It is a verified link directly from Bohemia. I am just trying to help the people while promoting a Market that is in my opinion the best option right now) Also the staff is real active and efficient in resolving disputes if ever there is one. Something with this guys just makes me feel safer for some reason.
StarScream9992022-05-2449980b20
I've verified the vulnerability myself the moment I saw Sixty post it, and I can tell everyone it was indeed read-only. But like any compromise it was a foothold within the system which could have lead to further privilege escalation. While I never personaly used Versus, they were indeed one of the few markets who were actually transparent. And thay can't be said for any other operation, they had a good run, let their users finalize transactions and withdraw coins. All in all an end of an era.
Google2022-05-2492b74da0
"Unless the international po po were sitting on their hands, data was leaked." Let's hope everyones data from Versus isn't sitting on an FBI server right now... damn. The law is always 3 steps behind though, so maybe not. The markets are only splintering further. Cannahome is gone, Versus, and WhiteHouse. The game is in a tail spin right now. There's vendors that I've totally lost contact with in the past 6 months that I'd love to find again. Never had this problem. Fuck mane
whow2022-05-24b9e20e80
nah desnake is doing good moves paris has nothing to do with all you can see versus admin confirm the exploit i hope no le has the info or we are all fked
fuvkversus2022-05-2450025d30
t-the vulnerability wasnt critical and le dont have anything t-thats why were are shutting down forever absolute state of versus junkies thank you for your support and being part of something that hopefully defined the future of DNM’s.” defined literally nothing but an exposed ip and shit support what a delusional post
Allison Wick2022-05-24c964df50
I needed a hacker for a very and strict and confidential job, he did it so well without any comebacks or tracebacks was able to get all my crypto . For those in need of a qualified Black Hat hacker who shows proof before hack not on the clear net wizcyber on Wickr (might have to download wicker), or Do mention Sally as he can be TOO WARY!
ANNEFRANK2022-05-2416168cd0
OYYY VEY VERSUS HAD 4 GORILLION USERS ALL WIPED OUT IN THE SHOAH NEVER FORGET GOY desnake stole all our shekels because he exposed our exploit that was being used by police it is his fault we closed down goyim not our fault we dont know how to code OYYYY VEEEY DESNAKE IS PUTTING ME IN THE GAS CHAMBER AS I TYPE THIS HELLLLLP THE ANTISEMITISM
imjlfn752022-05-24e5ea8440
do we know who the hacker was/is? Law Enforcement? If so, do we change names and addresses again?
snakedog2022-05-26eb411550
Didn't look so legendary last summer when he went crying to dread about mr_white taunting and ddosing him into oblivion both over tor and his precious i2p eeps. It was gory. Mr_White had him on his knees begging for mercy. Look it up. Legendary security my ass. White is King.
DeCat2022-05-25e67db0a0
Desnake is one of the best security expert on deep web that i known. Honor and respect for an real ethical hacker :)
someyungG2022-05-25e41af590
To be honest, I've used Versus for a couple of years now and enjoyed their services but it took a while because Multi-Sig wasn't that easy for a lazy beginner like me to use as I was barely getting the hang of encryption/decryption/signatures and what not. After that learning curve, it wasn't too bad but the lag time on the market wasn't that great as well. Nonetheless, I was able to order successfully a few times and after getting used to that, it closed down. Luckily I still know my favorite vendor's private channel to order via e-mail ([email protected] & [email protected]). You can validate their public PGP key with the same one from their CannaHome & Versus channels.
jonnyfive2022-05-2509956f30
Been a sql and server admin and coder for years. Quite difficult to understand what kind of exploit they had and why it couldn't easily be fixed. To be honest to blame such a fundimental issue like that is kinda sus if you ask me. I suspect the fact they shutdown (assuming this is true) and didn't fix this supposed bug is the bigger bit of information. With that in mind what does this mean? I think it means they know they were compromised and shut down before something worse happened. Or perhaps it was something beyond the scope of fixing but I do find this quite hard to believe.
deesnutz2022-05-2561a89280
Asap is ok hopefully that doesn't go down next. So far I've found my main bud vendor on there. I really like ld versus it sucks... Anyways I hope that it's not a big huge deal I mean I always encrypted my addy and I only got small stuff mainly thc products no more than a half p at a time. If the feds do have a he data then oh well I guess they know I smoke hella weed lololol
imjfln752022-05-25691cd620
I dont know. I had something marked shipped on the 19th and it never made it. I dont believe in coincidences.
Cryptoluci2022-05-256e0757d0
So... How do the customers go about contacting the vendors if we never received our orders? They aren't creating an open p2p option for vendors-customers?
LE2022-05-2769f7bac0
bless u, you make my job so much easier "First rule in government spending: why build one when you can have two at twice the price?"
4-049302022-05-26c44628b0
Now the next targeted market is alphabay 2.0 no one knows how long it will survive.
alians2022-05-301fc92cf0
Versus felt very amateurish from the beginning. Just glad I didn't lose any money this time. Does seem weird that they just shut down when someone found a huge bug. where the fuck did they get the code anyways?
esr2022-06-01dc29f080
probably from stackoverflow. i really do hate those kind of retards, that get bad code and stick it to their website without checking it. the fact that the backend was php doesn't helps
stoner2482022-06-09b5cdf8f0
what do they mean they'll released a link for vendors to withdraw their time-locked money earlier? Has it been released?
cokeandmore2022-05-24466e3150
You sound like an angry child that got banned from their market. I was a vendor on versus and it was the best experience I had in years. They were always fair and honest. The interface was just perfect. I never lost a single dollar. Not even now! I downloaded all locktime transactions every day and I can get my money in a couple of month. All other markets fucked me up big time and stole my money. I can only say thank you william and the rest of the team. It was a pleasure to sell on your market! You deserve the retirement!
yeye2022-05-259b2525e0
Not to mention the silly childish seeds for accounts: 'cunt piss ass dick boobs' Good riddance in dead
lulz2022-05-2710b9a900
u might be on to something about the darknets hmmmmmmmm now, do the ponzi, I mean crypto
cuck2022-05-283330bcb0
sure thing task force for the street rats who don't know wickr is backdoored for LE as confirmed by the 2014 on-wards revolutions
IPv42022-05-244d05bfa0
Thanks DNL, squaring in big time there, finally the official statement. My thoughts: it was indeed a read only vulnerability, allowing LE, DeSnake, 666ty and unknown others to access the market databases since the creation of the website, kind of hard to put a take down banner on a vulnerability like that... So why did they shut down if it wasn’t a critical vulnerability? IP addresses are a bitch of read only information… 🖼