# Gitea just may have been hacked

**URL:** <https://forum.gitea.com/t/gitea-just-may-have-been-hacked/8322>\
**Category:** General\
**Created:** [December 18, 2023, 7:47pm UTC](https://forum.gitea.com/t/gitea-just-may-have-been-hacked/8322 "2023-12-18T19:47:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![RightFootConsulting](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/rightfootconsulting/32/4281_2.png) [@RightFootConsulting](https://forum.gitea.com/u/RightFootConsulting)\
**Post date:** [December 18, 2023, 7:47pm UTC](https://forum.gitea.com/t/gitea-just-may-have-been-hacked/8322/1 "2023-12-18T19:47:08Z")

</div>

I went to validate the latest download using the asc file here  
https: // [dl.gitea.com/gitea/1.21.2/gitea-1.21.2-linux-amd64.asc](http://dl.gitea.com/gitea/1.21.2/gitea-1.21.2-linux-amd64.asc)

But that doesn’t look like any kind of ASCII file I have ever seen see this gobledy gook:

□3  
!□d□□g□□□□$□E\_□F2□S□□ex□  
□□□| \_□F2□S□□I□□□aT\<□□}܊□@.  
□+□□2□□□h□□(p□q/_Q~□]�□,□ҳ□□?□□w□’d_4□H  
r□=□□z□RG□[PQI^nL0□η  
7x_□□u □□1x□□□Q□⸮□,\>□□A[□□FḎ□□□□□□sW□z~□)□k□□M)𕀩□  
%a7□cJ□□□□s□~□□□v  
□□□□/□߽Q□□nL]□□W□T□□□F□ □□I,□Xx□□□4□$□□□g□S□i~□@□  
Q[□□□E’□O□□46□□)□□□□□tŁ□□□t□,□.□~□\_R□:□□P□□&d□□□e□□□□□□□□F□□#□ׂ?yO□.□□/□□\_□□$xav4□a□□mL□fd^□9C?□□R□g□□□□.□+□J□և,[□□@□□□□`Z6 Ȫ□c□]□8□^9□"□@□:|□ol□□H□□□□f□c□a□v's□□6X□□;□□i□□{□`T□□\<q□□□U□Ў□I□y0Pa□□□j(□mz҆#\<t□□□,□E ١□□□□□_□Q□}□□□U□□□□□□□Ԛ□7□r

and when you validate with it you get:

gpg: Signature made Tue 12 Dec 2023 06:54:12 AM UTC  
gpg: using RSA key CC64B1DB67ABBEECAB24B6455FC346329753F4B0  
gpg: Good signature from “Teabot \<teabot @ [gitea.io](http://gitea.io)\>” [unknown]  
gpg: WARNING: This key is not certified with a trusted signature!  
gpg: There is no indication that the signature belongs to the owner.  
Primary key fingerprint: 7C9E 6815 2594 6888 62D6 2AF6 2D9A E806 EC15 92E2  
Subkey fingerprint: CC64 B1DB 67AB BEEC AB24 B645 5FC3 4632 9753 F4B0

---

<div class="post-metadata">

**Author:** ![lunny](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lunny/32/4701_2.png) [@lunny](https://forum.gitea.com/u/lunny)\
**Post date:** [December 19, 2023, 1:41am UTC](https://forum.gitea.com/t/gitea-just-may-have-been-hacked/8322/2 "2023-12-19T01:41:00Z")

</div>

No, I can confirm it’s normal. You need to update your key first.  
ref: [https://docs.gitea.com/next/installation/install-from-binary?\_highlight=download#verify-gpg-signature](https://docs.gitea.com/next/installation/install-from-binary?_highlight=download#verify-gpg-signature)
