In early December 2025, attackers exploited a critical React and Next.js vulnerability to take cryptocurrency balances out of SellAuth merchant accounts. SellAuth has never disputed that it happened. It replied publicly to affected sellers on Trustpilot, named the vulnerability as the cause, and promised that "every affected merchant will receive the full amount of their missing funds".
On December 24, 2025 it said the process was "expected to finish by the end of the year or early January". On March 23, 2026, replying to a seller who was still waiting, it said reimbursements "have already begun" and dropped the completion date. No public announcement says the process ever finished.
Everything else about SellAuth is ordinary and some of it is good: 0% on all three plans, priced at $0, $9.99 and $29.99, with a custom domain at $9.99 that undercuts most of this category including ByteSell. Two things should decide it for you. The largest file any plan can deliver is 100 MB, and there was a crypto balance sitting on the platform for an attacker to reach in the first place.
SellAuth answered the reviews itself, in public and under its own name. Two of those exchanges, three months apart, carry most of the story.
The Platform Steals Your Payments
They said there is a security breach in the crypto for 5% of sellers but every seller I contacted was affected by this security breach. I lost $200 by this security breach and its obviously just them just scamming, taking your money. They just now said half of the sellers have been compensated but no one did. Update: I just got banned on their discord server for protesting this.
Reimbursements have already begun, and every affected merchant will receive the full amount of their missing funds. The process is expected to finish by the end of the year or early January.
The vulnerability is real and it is as serious as SellAuth says. React2Shell, tracked as CVE-2025-55182 for React and CVE-2025-66478 for Next.js, is an unauthenticated remote code execution flaw in the React Server Components protocol. It scores 10 out of 10, and attackers used it to steal cryptocurrency across hundreds of hosts. SellAuth is right that it hit a great many companies, and that is not the question a seller needs answered.
Here is the same company three months later, replying to somebody who was still waiting.
Owner is Big Scamer & Platform was hacked
So this platform was hacked, and our all funds were looted out by hacker. The owner promised us to refund the amount but they didn't do any refund or announcement, they delayed the refund for 2 months then we ask for the refund they give me give out for 15 days for 2 times. Please do not use this platform the owner and support is pathetic
Reimbursements have already begun, and every affected merchant will receive the full amount of their missing funds. We appreciate your patience as this process is being completed.
December 24: reimbursements have already begun, finishing by early January. March 23: reimbursements have already begun, and the finishing date is gone. It is the same sentence in the same tense three months later, which is what a seller weighing up SellAuth has to sit with.
A third seller, writing in the same week as the first, adds that there is no contract behind any of it.
THEY ARE ALREADY SCAMMING (MUST READ)
They are already scamming with "security breach" with crypto, we know this is bullshit, they claimed that half of the sellers have been compensated and every seller I know has not been compensated. So they are scamming with crypto payouts, stay away if you have a brain. They are trying to look as legit as possible, but they have no kyc or contracts, so nothing is secured or official, they will continue to scam later on and you will just waste your time on this platform.
The first of those three sellers also says he was banned from SellAuth’s Discord for protesting about the missing money. That is his account of it, and nobody outside the server can check what happened there.
Take the names out and this is a custody story. A hole in a widely used framework handed an attacker the ability to run code. Because merchant crypto balances were sitting on the platform, there was something there to take. Every affected seller then became an unsecured creditor of a company they have no contract with, waiting on a timetable they do not control.
Being non-custodial does not make a platform immune to a vulnerability like this one. It changes what is at risk when one lands. If buyers pay your own Stripe, PayPal or crypto wallet directly, a compromised storefront is an outage: expensive and infuriating, and your revenue was never in the blast radius, because there was no balance to drain. That is how ByteSell is built, and it is why the question of who holds the money is one to ask before something goes wrong rather than after.
SellAuth holds a 3.0 on Trustpilot across 114 reviews, and the shape of that average says more than the number does: 48% are five star and 46% are one star, with almost nothing in between. The complaints in the one-star half start six months before the breach and carry on after it.
Good if you wan't to lose money
Sellauth itself is an "OK" concept, however they are really awful. Daily downtime (I wish I kidding), sometimes even taking hours/days, making you lose a lot of money. Features missing, your custom domain not working, can't even upload images and terrible/non-existent support/developer. Always blaming cloudflare or ddosers for their issues but let's be honest, they are just lazy and bad.
Over the past month, Sellauth has been extremely unreliable on both the customer and seller sides. The site constantly breaks, with frequent downtime and no easy way to view real-time status updates. For the last 48 hours, I’ve been unable to sell or purchase anything using their crypto service. They only support Bitcoin and Litecoin, with no options for other major cryptocurrencies that most users prefer. CAPTCHA failures happen often on store pages, and modal integrations load very slowly. Now, additional issues have appeared: the login button on the main page doesn’t work, the Discord link redirects to an undefined page, and both the Terms of Service and Acceptable Use Policy pages on the dashboard return 404 errors. Overall, the platform feels broken, unstable, and poorly maintained.
The most recent of them is also the most credible, because it is a downgrade rather than a first impression. This seller had hosted their stores on SellAuth and had left a five-star review before.
Scammed me, insanely slow support, bad backend.
Edit: They finally let me know the funds have been released since posting this review, however they completely denied my abuse report even though the seller is using SellAuth for their backend. I had previously used SellAuth to host my stores and even left a 5-star review since I had a positive experience, however that drastically changed over the past 2 months. This is my experience: 1. Their crypto payment system broke which led to a customer's order not being automatically completed and me having to manually complete it, funds weren't sent to me either. I opened a ticket 30 days ago and still haven't received my funds, just my ticket being ghosted the entire time. 2. Another seller on the SellAuth platform copied entire pages & design elements from my site, so I opened an abuse report ticket. They took 10 days to reply just to say their website wasn't hosted on SellAuth, although I checked DevTools and there's multiple SellAuth backlinks so they just lied in my face (they can easily see in their system this is a seller). 3. Their backend is decent however the Code Editor is in Nunjucks which makes it nearly impossible to import your own frontend without UI bugs. Every custom-coded SellAuth website I’ve seen has had super slow page navigation speeds, which is the main reason I switched away from using SellAuth since I needed a new frontend design and their platform wasn't feasible for that. I still have my 2 tickets open (#bug-14658 & #abuse-15177) so it’d be great if SellAuth sees this and can get this sorted, I didn't want to have to resort to leaving a negative review since I rarely do but no action is being taken here even with me addressing the slow support in their public chat.
Note the edit at the top of that one. The funds were released after the review went up. It took a public one-star to move a ticket that had been open for thirty days.
This is the number that decides whether SellAuth can host your business at all, and it lives in the comparison table rather than on the plan cards. "Downloadable Files" reads 100 files at 10 MB on the free plan, and 500 files at 100 MB on Business. On Scale, the $29.99 plan, it reads exactly the same as Business: 500 files at 100 MB.
So the largest file a SellAuth store can deliver is 100 MB, and paying three times as much does not raise it. For an ebook, a licence key or a preset pack that is irrelevant. For a game mod, a sample library, a video course or a Unity asset it is the entire decision. ByteSell allows 50 MB on its free plan, 10 GB on Pro and 25 GB on Business. Team seats work the same way: 2, 10 and 50 across SellAuth’s three plans, where ByteSell caps team members on none of them.
0% transaction fees, up to 50 products, 25+ payment methods, basic fraud protection, API access and embeds, on a SellAuth subdomain with SellAuth branding.
Business, $9.99 a month
Adds a custom domain and custom pages, 500 products, an affiliate system with 10 tiers and 500 affiliates, fraud shield with VPN, TOR and country blocking, custom email templates and SMTP, and the Checkout API.
Scale, $29.99 a month
Adds the Marble premium theme, 5,000 products, the reseller system and panel, feedback on any order with no minimum, and priority dispute resolution.
A custom domain at $9.99 undercuts ByteSell Pro at $29, and the fraud blocking sits on that same tier. On price alone SellAuth is cheaper and it is not close.
One oddity to clear up before paying: both paid plans print a monthly price and then, directly underneath, the words "One-time payment · no auto-renewal". The page never reconciles those two statements. Ask which one governs.
So the decision comes down to what you sell and how much you mind a balance. If every product you have fits under 100 MB, price is the constraint you feel most, and you are willing to empty the platform balance rather than let it build up, then SellAuth at $9.99 is a cheap way to run a shop and the reviews on the five-star half of that split were not written by nobody. If any of your products is larger than 100 MB, or you would rather your revenue never sat on a platform in the first place, neither of those is something you can configure your way around, and the answer is a store where the money keeps moving on its way to you. ByteSell costs nothing to start and 0% on every plan, files run to 10 GB on Pro, and buyers pay your own Stripe, PayPal or wallet, so there is no balance for the next vulnerability to find.