the existence of a vulnerability which allowed him to stealAttack.Databreachover 200,000 private messages exchanged between users and sellers . Earlier this week , the hacker , known only as Cipher0007 , disclosedVulnerability-related.DiscoverVulnerabilitythe existence of two `` high-risk '' bugs through Reddit . In a forum post , the hacker saidVulnerability-related.DiscoverVulnerabilitythe two security flaws could be exploitedVulnerability-related.DiscoverVulnerabilityto snatch private messages . Cipher0007 was able to compromiseAttack.DatabreachAlphaBay and stealAttack.Databreachthe first and last names of buyers and sellers , nicknames , addresses , and the tracking IDs of packages sent by traders when included in the messages and not protected by PGP keys . The hacker also issued a number of screenshots of private messages as proof , which revealed the messages were not encrypted by default . After disclosingVulnerability-related.DiscoverVulnerabilitythe vulnerabilities on Reddit , Cipher0007 opened a number of support tickets on AlphaBay , warningVulnerability-related.DiscoverVulnerabilitythe Dark Web trading post of the potentially devastating bugs which could compromise the privacy and identities of users . In a statement on PasteBin , AlphaBay confirmedVulnerability-related.DiscoverVulnerabilitythe validity of the vulnerabilities and saidVulnerability-related.DiscoverVulnerabilitythe bugs allowed the hacker to slurpAttack.Databreacha total of 218,000 messages which were not older than 30 days . Older messages are automatically purged from the system . The attacker was paid for disclosing the flaws rather than selling them on or releasing the stolen information to the public . In return , Cipher0007 revealed his methods and several hours later AlphaBay developers were able to close the loopholesVulnerability-related.PatchVulnerability. As Dark Web marketplaces must provide strong assurances that users will remain anonymous due to the nature of goods sold there , often illegally , these kinds of vulnerabilities have the potential to destroy such businesses . Alternatively , these security flaws would be of interest to law enforcement agencies attempting to close down such operations -- and may have been knownVulnerability-related.DiscoverVulnerabilityto them before the hacker discoveredVulnerability-related.DiscoverVulnerabilitythe bugs . Unless users indulging in risky , illegal trading take responsibility for their own privacy by using PGP keys and personal encryption , they can not cry foul if their personal information is leakedAttack.Databreach