Avatar
4chan Blog

April 2025

Still standing

On the afternoon of April 14th, a hacker using a UK IP address exploited an out-of-date software package on one of 4chan's servers, via a bogus PDF upload. With this entry point, they were eventually able to gain access to one of 4chan's servers, including database access and access to our own administrative dashboard. The hacker spent several hours exfiltrating database tables and much of 4chan's source code. When they had finished downloading what they wanted, they began to vandalize 4chan at which point moderators became aware and 4chan's servers were halted, preventing further access.

Over the following days, 4chan's development team surveyed the damage, which to be frank, was catastrophic. While not all of our servers were breached, the most important one was, and it was due to simply not updating old operating systems and code in a timely fashion. Ultimately this problem was caused by having insufficient skilled man-hours available to update our code and infrastructure, and being starved of money for years by advertisers, payment providers, and service providers who had succumbed to external pressure campaigns.

We had begun a process of speccing new servers in late 2023. As many have suspected, until that time 4chan had been running on a set of servers purchased second-hand by moot a few weeks before his final Q&A, as prior to then we simply were not in a financial position to consider such a large purchase. Advertisers and payment providers willing to work with 4chan are rare, and are quickly pressured by activists into cancelling their services. Putting together the money for new equipment took nearly a decade.

In April of 2024 we had agreed on specs and began looking for possible suppliers. Money is always tight for us, and few companies were willing to sell us servers, so actually buying the hardware wasn’t a trivial problem. We managed to finalize a purchase in June, and had the new servers racked and online in July. Over the next few months we slowly moved functionality onto the new servers, but we had still been relying on the old servers for key functions. Everything about this process took much longer than intended, which is a recurring theme in this debacle. The free time that 4chan's development team had available to dedicate to 4chan was insufficient to update our software and infrastructure fast enough, and our luck ran out.

However, we have not been idle during our nearly two weeks of downtime. The server that was breached has been replaced, with the operating system and code updated to the latest versions. PDF uploads have been temporarily disabled on those boards that supported them, but they will be back in the near future. One slow but much beloved board, /f/ - Flash, will not be returning however, as there is no realistic way to prevent similar exploits using .swf files. We are bringing on additional volunteer developers to help keep up with the workload, and our team of volunteer janitors & moderators remains united despite the grievous violations some have suffered to their personal privacy.

Apr 26, 2025

598 notes
#4chan

November 2015

4chan update on these days.

/his/ was born.

Homepage image changed a bit on Nov 5th.

Nov 06, 2015

52 notes
#4chan

September 2015

4chan is now owned and led by Hiroyuki Nishimura, the founder of the largest anonymous BBS in Japan, 2channel. Read the full announcement on the 4chan News page.

Sep 21, 2015

134 notes

January 2015

I'm retiring after serving as 4chan's founder and administrator for more than 11 years, from the age of 15. You can read the full announcement on the 4chan News page.

—moot

Jan 21, 2015

1,169 notes
#4chan #moot #retirement #mootxico #goodnight sweet prince

New requirement for 4chan volunteers going forward

Recently we introduced a new requirement for 4chan's volunteer moderators and janitors, which is that they sign a volunteer agreement that puts in writing a number of things that have always been true, namely that:

  • Moderating 4chan is a volunteer position and not a real "job" in any sense of the word (yes, they truly do it >for free), however we expect volunteers to conduct themselves in a professional manner and in accordance with the moderation guidelines and training we provide.
  • Volunteers are expected to hold in confidence any and all private information they come into contact with, especially regarding our users, and they are not to use or disseminate that information except to perform their volunteer duties.
  • In addition to signing this formal agreement, we now require proof of identity from all volunteers, present and future. Why? So we can enforce the agreement should it be violated (ie. user information being misused, leaks, etc) and establish a liability barrier in between the company and its volunteers.

    Most large websites with analogous volunteer roles use similar agreements, and we were long overdue for one of our own. You can find a full copy of the agreement below (note this will be mandatory as of our next janitor drive):

    Jan 18, 2015

    117 notes
    #4chan #moderator #janitor

    December 2014

    The future of 4chan Pass

    As many of you know, last week we upgraded to the new reCAPTCHA API, bringing CAPTCHA-less posting to the masses >for free. Since the upgrade, approximately 25-30% of daily solve attempts encounter no CAPTCHA at all, with failure rates hovering at an all-time low of 6%.

    Alongside the new CAPTCHA, we temporarily disabled the sale of 4chan Passes as we evaluated whether or not to continue supporting them in light of the change. Ultimately, we decided to resume offering 4chan Passes for sale for those who don't want to deal with CAPTCHA at all, would like to post from behind a blocked IP range, or just plain want to support the site.

    We've also decided to offer a limited time, pro-rated refund to those who currently hold an active 4chan Pass that was purchased on or before December 8th, 2014. While we don't normally offer refunds for Pass purchases, we felt it was best to provide an opportunity for users who feel their Pass has been devalued as a result of the CAPTCHA change to request a pro-rated refund.

    Since 4chan relies primarily on Pass sales to make ends meet, we'll continue to sell and support them for the foreseeable future, and may consider adding additional features at a later date and time (ideas welcome).

    If you'd like to submit a refund request for your active 4chan Pass that was purchased on or before December 8th, please visit this link and follow the instructions.

    Dec 17, 2014

    86 notes
    #4chan #4chan pass #captcha

    No CAPTCHA reCAPTCHA

    Two days ago, we upgraded to the new reCAPTCHA API, dubbed the "No CAPTCHA reCAPTCHA".

    The new API allows users determined to not be spambots to bypass typing a verification, giving them a CAPTCHA-less posting experience. Below you can see the change from our last full day using the old version of the API to our first full day using the new version:

    Dec 10, 2014

    83 notes
    #4chan #captcha #recaptcha

    November 2014

    Mobile site improvements and change to moderation

    The mobile site has received a slew of updates recently, including:

  • The ability to view original filenames and truncated names/subjects (tap the file size or inline expand the image; tap truncated text to expand).
  • Support for infinite scroll (tap "Load More" at the bottom of board indexes, or check "Always use infinite scroll" in Settings).
  • A dark theme (Tomorrow) for nighttime browsing, enabled in Settings under "Miscellaneous."
  • Top navigation now auto-hides upon scrolling down to free up vertical space for reading threads. Scroll up to have it reappear.
  • Nov 20, 2014

    113 notes
    #4chan #mobile #moderation

    Enhanced Thread Watcher, unique posters, and delayed pruning

    Three new features, and a belated announcement:

  • The Thread Watcher can now auto-watch threads based on filters you've set in the "Filters & Highlights" menu. It works by fetching catalog JSON and matching filters against OPs on the specified board(s). Note that auto-watching only works when you select individual boards for a filter ("Boards" can't be blank) and manually refresh the Thread Watcher, due to client-side CPU/bandwidth concerns (we may add a user specifiable timer in the future).
  • Threads now display the number of unique posters in a thread (based on IP). We're trialling this as a way to give users an idea of how many active contributors there are in a given thread.
  • Delayed pruning was expanded to all boards except for /b/ some weeks ago. Per the original announcement, once a thread expires it is retained for a period of 48 hours before being pruned.
  • —moot

    Nov 09, 2014

    52 notes
    #4chan

    August 2014

    Sayonara E-mail field, and delayed thread pruning

    Today we're making two noteworthy changes:

  • The E-mail field has been replaced with Options. This field had mainly been used for posting options such as sage and dice-rolling. If a user wishes to provide contact information, they can do so in the Comment field.
  • We're trialling delayed thread pruning on specific boards. While not a true archive, threads on /a/ and /v/ will continue to be accessible for a period of 48 hours after being pushed off of the board index. We may roll this out to additional worksafe (blue) boards in the future, as well as increase or reduce the retention period.
  • —moot

    Aug 12, 2014

    162 notes
    #4chan

    June 2014

    IPv6 support for 4chan

    Today we're pleased to announce support for IPv6 on all of 4chan's domains, thanks to CloudFlare's new Pseudo IPv4 feature.

    CloudFlare's CEO, Matthew Prince, goes into more detail on their blog, but essentially they'll accept traffic from our users over IPv6-enabled networks and route the request to our backend using plain ol' IPv4. This removes the need for our application to be updated to natively support IPv6 (something we're working on, but is a ways off).

    Since IPv6's address space is considerably larger than IPv4, the mapping of IPs won't be one-to-one, however they believe it's large enough to accommodate the transition period between now and applications having true IPv6 support.

    If you're using an IPv6-enabled network you may see a slight performance benefit should your ISP have better routes to CloudFlare's datacenters that way.

    Update: This change was reverted due to issues with our ban system, however our static content hosted at 4cdn.org is still accessible via IPv6 networks.

    Jun 06, 2014

    64 notes
    #4chan #cloudflare #ipv6

    May 2014

    Announcing 4chan's Vulnerability Disclosure Program

    In response to last month's intrusion, we've put numerous additional security measures in place in an effort to mitigate and prevent future intrusions.

    We're also pleased to announce the creation of 4chan's Vulnerability Disclosure Program—commonly known as a "bug bounty."

    We hope that by providing an officially sanctioned way for security researchers to submit security-related bugs, we'll be in a better position to detect and respond to vulnerabilities that may impact the site and its users.

    Security remains an ongoing priority and commitment of ours. Thanks again for bearing with us, and sorry to anyone we've let down.

    —moot

    May 06, 2014

    92 notes
    #4chan #hackerone #responsible disclosure #hacking

    April 2014

    Concerning a recent intrusion

    Last week we were made aware of a software vulnerability that allowed an intruder access to administrative functions and information from one of our databases. The intruder later stated their motive was to expose the posting habits of a specific user they disliked.

    After careful review, we believe the intrusion was limited to imageboard moderation panels, our reports queue, and some tables in our backend database. Due to the way the intruder extracted information from the database, we have detailed logs of what was accessed. The logs indicate that primarily moderator account names and credentials were targeted.

    Three 4chan Pass users had their Pass credentials accessed, and were notified and offered refunds and lifetime Passes shortly after the discovery. As a reminder, all payment information is processed securely by Stripe—we never see nor store any of it, and thus no payment information was compromised.

    We patched the vulnerability quickly after it came to our attention, and have spent—and will continue to spend—dozens of hours poring over our software and systems to help mitigate and prevent future intrusions.

    We're sorry it happened, and will do our best to ensure it doesn't happen again.

    Apr 30, 2014

    139 notes
    #4chan

    Upcoming namespace changes

    In the coming week, we'll be making a few changes to how files are accessed. The changes are mostly cosmetic, and will be transparent to people using vanilla 4chan. We'll also continue to support legacy URLs for a short time to give third-party developers the opportunity to migrate their apps, but suggest making the appropriate updates as soon as possible to be prepared for when the changes go live.

  • Semantic thread URLs with slugs. "res/" will be renamed to "thread/", and subject/comment snippets will be appended after the thread ID as a slug. For example, "http(s)://boards.4chan.org/g/res/41321419" would become "http(s)://boards.4chan.org/g/thread/41321419/daily-programming-thread". This will be included in the JSON as the "semantic_url" attribute in the OP container.
  • Less redundant file URLs. The "src/" and "thumb/" directories will be removed from images/thumbs.4chan.org and i/t.4cdn.org. Files will live at the board root on those subdomains.
  • Pages renumbered. The board index will now start from "Page 1" instead of "Page 0".
  • The 4chan API documentation will be updated shortly before the changes go live.

    Apr 12, 2014

    60 notes
    #4chan

    Goodbye to some old friends

    Yesterday we welcomed two old features back to the site—the 4chan Blog and Blotter—but today we'll also say goodbye to a few.

    Over the past 10 years, 4chan has accumulated many features and side-projects, but since the team has rarely consisted of more than myself, a single volunteer developer, and a handful of volunteer moderators, many have been neglected. Specifically the discussion boards (dis.4chan.org) and Fileshares board (rs.4chan.org).

    Rather than continue to neglect these side-projects, we've decided to retire them so that we can focus our time and energy into maintaining and improving the core of the site—4chan's image boards.

    The discussion boards will continue to live on in a read-only state, while the Fileshares board will be shut down. Both will be frozen and de-linked soon.

    For the VIPPERs and ``expert programmers'' among us this may be a sad day, however we hope to accommodate you with some future image board features. Stay tuned.

    Apr 07, 2014

    102 notes
    #4chan

    WebM support on 4chan

    Today we added support for WebM files on 4chan's image boards.

    While WebM is technically a video file format, it offers many advantages over animated GIFs—namely superior image quality, support for more than 256 colors, and reduced file size. Its main disadvantage is browser compatibility, however 86% of 4chan's visits come from browsers that include full or partial support for WebM, and plug-ins are available for those that don't (like Internet Explorer and Safari).

    We decided to disallow WebM files with sound for a few reasons, but mainly because it's our intention to provide the site with better animated images, and not true video support. To that end, we only accept WebM files with one video stream and no audio streams, that are shorter than 120 seconds long, no larger than 2048x2048 pixels, and less than 3 MB in size.

    We're eager to see how 4chan's users will adopt WebM, and have posted this short guide on encoding them to ease adoption. Many thanks to desuwa for both championing and implementing this feature.

    —moot

    Apr 06, 2014

    205 notes
    #4chan #webm

    Reintroducing the 4chan Blog and Blotter

    Long-time users will remember the late 4chan DevBlog and Blotter, which were removed almost five years ago due to infrequent use. We had used them to share updates with the community that didn't require lengthy news posts.

    Today I'm pleased to reintroduce both. As someone who hates writing and prefers to publish news posts only when absolutely necessary, I welcome their return. We'll continue to use the global message (big red text at the top of boards) to communicate important notices, but will use the blog and blotter to share a running tally of smaller updates.

    You may not realize it, but we're constantly working behind the scenes to improve the site—be it feature additions, code tweaks, or improving moderation. It's our hope to give the community more visibility into those improvements via a changelog of sorts.

    So give us a follow or subscribe via RSS, and keep an eye on the blotter.

    —moot

    Apr 06, 2014

    132 notes
    #4chan
    Join over 100 million people using Tumblr to find their communities and make friends.