Jun 10, 2026, 04:39 AM
We are Orcinus orca — the apex predators of the digital deep
Greetings BreachForums,
Today I am dropping a small piece of evidence showing deep access into Wickr Enterprise (Amazon AWS) infrastructure. This isn't just a dev environment; this is from the Production Admin API.
Key details of this leak:
HTTP/2 200
content-type: application/json; charset=utf-8
content-length: 111
x-envoy-decorator-operation: admin-api.wickr.svc.cluster.local:80/*
content-security-policy: script-src 'self' 'nonce-script_auto_trigger_button';
x-dns-prefetch-control: off
expect-ct: max-age=0
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=31536000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-permitted-cross-domain-policies: none
referrer-policy: no-referrer
x-xss-protection: 1; mode=block
access-control-allow-origin: https://342649xxxxxx-wickr-admin-pro-pro...amazon.com
access-control-allow-headers: Content-Type, X-Amz-Date, Authorization, X-Api-Key, X-Amz-Security-Token, X-Session-Nonce
access-control-allow-methods: GET, PUT, POST, DELETE, PATCH, OPTIONS
access-control-max-age: 600
access-control-allow-credentials: true
cross-origin-opener-policy: same-origin
cache-control: no-cache, no-store, must-revalidate, max-age=0
etag: W/"6f-e8xI/+iB0WzydMDyPkyXzq2RhVA"
{"plans":[],"publicAPIKey":"ewr1-Ingu3Klpkxq0Y2uWloogI6","brainTreeKey":"production_wn4yycvg_ntv52yxfg345hz3b"}
Greetings BreachForums,
Today I am dropping a small piece of evidence showing deep access into Wickr Enterprise (Amazon AWS) infrastructure. This isn't just a dev environment; this is from the Production Admin API.
Key details of this leak:
- Target: Wickr Enterprise Admin Services (AWS Infrastructure)
- Access Level: Internal Admin API (via CloudFront/Envoy)
- Exposed Data: Internal API Keys, Braintree Production Keys, and Envoy Decorator operations.
- Infrastructure Proof:
- access-control-allow-origin points directly to the AWS Internal Admin Console.
- Leaked publicAPIKey and brainTreeKey for payment processing.
- access-control-allow-origin points directly to the AWS Internal Admin Console.
HTTP/2 200
content-type: application/json; charset=utf-8
content-length: 111
x-envoy-decorator-operation: admin-api.wickr.svc.cluster.local:80/*
content-security-policy: script-src 'self' 'nonce-script_auto_trigger_button';
x-dns-prefetch-control: off
expect-ct: max-age=0
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=31536000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-permitted-cross-domain-policies: none
referrer-policy: no-referrer
x-xss-protection: 1; mode=block
access-control-allow-origin: https://342649xxxxxx-wickr-admin-pro-pro...amazon.com
access-control-allow-headers: Content-Type, X-Amz-Date, Authorization, X-Api-Key, X-Amz-Security-Token, X-Session-Nonce
access-control-allow-methods: GET, PUT, POST, DELETE, PATCH, OPTIONS
access-control-max-age: 600
access-control-allow-credentials: true
cross-origin-opener-policy: same-origin
cache-control: no-cache, no-store, must-revalidate, max-age=0
etag: W/"6f-e8xI/+iB0WzydMDyPkyXzq2RhVA"
{"plans":[],"publicAPIKey":"ewr1-Ingu3Klpkxq0Y2uWloogI6","brainTreeKey":"production_wn4yycvg_ntv52yxfg345hz3b"}

haha