Security notice

Statement regarding third-party security claims.

Published: 2026-08-29 · Last updated: 2026-08-29

Third-party websites and cybercrime forums have published claims concerning bitbybit Studio, including content using identifiers such as “DATABASE-2026-bitbybit-studio-25M” and descriptions referring to an alleged 25 million-record dataset.

These labels and figures originate from third-party and threat-actor claims. They should not be interpreted as verified findings by bitbybit Studio. Our investigation and incident-response work remain focused on establishing the verified scope, protecting affected information, and addressing public distribution of the material.

This page is the official bitbybit Studio source for verified information relating to those claims.

How to read this page

Public reporting on security matters mixes three very different kinds of statement. We keep them separate here, and we will keep them separate in anything we publish later.

Verified fact
Information independently established by bitbybit Studio.
Third-party claim
A statement made by a threat actor, security website, forum, researcher, or other outside source. Repeating a claim to address it is not the same as confirming it.
Under investigation
Information for which the investigation has not reached a final conclusion. We will not characterise scope, cause, or impact ahead of the evidence.

Questions and answers

What is DATABASE-2026-bitbybit-studio-25M?
DATABASE-2026-bitbybit-studio-25M is an identifier used by third parties in connection with claims about data allegedly associated with bitbybit Studio. The identifier, dataset size, and related technical claims originated outside bitbybit Studio and should not be treated as independently verified company findings.
Were 25 million records exposed?
A threat actor and subsequent third-party reports have referenced approximately 25 million records. bitbybit Studio does not adopt that figure as a verified scope unless and until it is independently established through the investigation.
Was a zero-day vulnerability responsible?
Third-party reports have described a zero-day vulnerability and various possible attack paths. Those claims should not be interpreted as bitbybit Studio’s confirmed root-cause determination. Root-cause conclusions will be based on verified forensic evidence.
Where can I find official bitbybit Studio security updates?
Official security information is published through the bitbybit Studio Security & Trust page. Operational updates are maintained at status.bitbybit.studio.

Where updates are published

Operational updates — current service state, maintenance, and operational security notices — are maintained on the public status page at status.bitbybit.studio. Standing first-party statements are published on the Security & Trust page, which is where this notice is listed.

Customers with questions about their own account or deployment can reach the team at [email protected]. Security researchers should follow the responsible disclosure process rather than reporting through public channels.