EVE Online fixes wallet-balance exploit tied to mass 0 ISK donations
EVE Online has patched a client vulnerability that let a player using a modified client view wallet balances by sending 0 ISK donations. The issue came to light after players started receiving a flood of empty donations on Friday, 4 September.
The EVE Online team says the exploit was fixed during the latest downtime and was not connected to the recent Python changes. The characters involved were banned, though the wallet-balance snapshots gathered during the incident may already be circulating.
According to the post, one player used four accounts to send roughly one million donations over about six hours, between 15:00 and 21:00 UTC. The exposed data was limited, but still sensitive in the very EVE-specific way wallet balances can be.
- Character ISK wallet balances were exposed as a snapshot at the moment of the donation.
- Corporation exposure was limited to the master wallet, not other wallet divisions.
- PLEX balances were not exposed.
- Transfers, transaction history, market orders, bills, assets, usernames, email addresses, and billing information were not exposed.
Players can check whether they were hit by looking in their wallet journal for an incoming 0 ISK donation on Friday, 4 September between 15:00 and 21:00 UTC. The named characters to look for are Mye Esubria, fxprobe1, fenriscw1, and Skiasten.
CCP says the balance snapshot does not update after the donation, and the fix prevents the exploit from being used again. The studio is still recommending two-factor authentication as a general account security step, even though 2FA would not have stopped this particular wallet-balance exposure.
Further reading: Official EVE Online security update






