hacking twitch chat

hacking twitch chat

🎙 John Hammond 👥 2.2M 📅 November 23, 2025 ⏱ 29 min 👁 31K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

TwitchStreamElementschat botcommand injectionvulnerability

Summary

In this video, John Hammond interviews Lethal Panda, a penetration tester, about a vulnerability discovered in StreamElements, a popular Twitch chat bot. The vulnerability allows users to inject commands through the bot’s variable system, potentially taking control of stream features or interacting with other bots. Panda demonstrates how the ‘args’ variable can be exploited to execute commands like /clear, /ban, and even change stream titles. The issue affects over 300 of the top 1000 streamers. Despite reporting the issue to StreamElements, they dismissed it as ‘intended behavior’. The video also explores the possibility of exploiting a time zone variable to access file system paths, though no full exploitation is shown. The discussion highlights the lack of security awareness in third-party Twitch tools and the potential for abuse.

127 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a real-world vulnerability in a widely used Twitch bot. The argumentation is solid, with live demonstrations and clear explanations of the attack vectors. The interviewer and guest effectively communicate the technical details, making it accessible to a technical audience. The value lies in raising awareness about the security risks of third-party integrations and the importance of proper input validation.

Scientific Rigor, Source Quality, Title Accuracy

The video is based on the guest’s personal research and demonstrations. No external sources are cited, but the live demos serve as evidence. The title accurately reflects the content. The discussion is technically rigorous, though it relies on anecdotal evidence and lacks formal documentation. The lack of response from StreamElements is highlighted, but the video does not provide official statements or further verification.

143 words

Title / Content Match

The title is concise and accurately reflects the content, which focuses on hacking Twitch chat through bot vulnerabilities.

Quality & Reliability

8/10

The video presents a detailed technical analysis of a vulnerability in StreamElements, demonstrated live with practical examples. The findings are corroborated by the fact that the issue was acknowledged and partially patched during the video. However, the lack of formal documentation or external verification slightly reduces the score.

Key Moments

Cited Sources

  • acid.wiki — Blog of Lethal Panda, mentioned in the description.
  • Just Hacking Training — Training platform mentioned in the description.
  • CodeCrafters — Affiliate link for learning to code.
  • CyberDefenders — Affiliate link for blue team training.
  • OpenVPN — Affiliate link for VPN hosting.
  • Newsletter — John Hammond's newsletter signup.

Concurring Sources

Contribution & Novelties

The video provides a novel analysis of a specific vulnerability in StreamElements, a widely used Twitch bot. It demonstrates practical exploitation techniques and highlights the lack of security awareness among third-party tool providers. The discussion encourages further research into the time zone variable, which may lead to more severe vulnerabilities.

Pour aller plus loin :

89 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and technical level, with a slightly lower but still strong score in global reliability. This indicates a well-presented, technically detailed video with credible demonstrations, though lacking formal external verification.

Reliability 8/10

💬 The comments are predominantly positive, with viewers expressing amusement and appreciation for the technical content. Some comments highlight the irony of StreamElements dismissing the issue as intended behavior, and others share similar experiences with other bots. The overall sentiment is enthusiastic and supportive.