The August 2026 digital storefront shutdowns: what is known, what is not, and how to choose a platform
On or about 3 August 2026 five platforms that digital-goods sellers depended on went dark at once. This page separates what is established from what is claimed, lists what sellers lost, and turns the lessons into a checklist for choosing the next platform.
What happened
On 2 August 2026 a thread opened on BlackHatWorld reporting that Billgang, Antistock, Sellpass, Forebit and Hoodpay had become unreachable. By 3 August, posters reported, the domains answered with fbi.seized.gov nameservers, and each site displayed a page titled "Seized by the Federal Bureau of Investigation". The posters describe the five as one connected operation, covering two storefront platforms (Billgang and Antistock, the latter the late-2025 rebrand of Sellpass), a wallet (Forebit) and a processor (Hoodpay); the operators had reportedly denied common ownership. A competing platform, Sellup, published the same account on 3 August and put Billgang's merchant base at roughly 7,500 businesses, a figure we have not verified.
Sources: BlackHatWorld thread, opened 2 August 2026 · Sellup blog, 3 August 2026
What is established, and what is not
Established: the five domains are unreachable and display the banner. On 18 September 2026 we queried the registry (TLD) nameservers for .com and .io directly, then the zones themselves, and read the whois records. Every one of the five sites, including their docs, support and API subdomains, returned the banner.
Not established: that any law-enforcement action took place. The zones answer with fbi.seized.gov nameservers, but the registries still delegate all five domains to the operators' own Cloudflare nameservers, the registrar is still Cloudflare, and the whois records were updated after the outage (26 August for Antistock, Sellpass and Forebit; 5 September for Billgang; 15 September for Hoodpay). We found no Department of Justice or FBI release naming any of the five as of 18 September 2026. The contrast case is Sellix: it went offline on 29 January 2025, the DOJ announced the seizure the next day, and the .io registry itself delegates sellix.io to fbi.seized.gov. The August 2026 domains do not show that registry-level pattern.
Attributed: posters on BlackHatWorld read the sequence as an exit scam. They cite a forced "v2" upgrade prompt in the weeks before the outage, after which their crypto balances appeared in new platform wallets labelled "wallet_compacted" for which they held no keys, and they relay that the operators cited a "security breach affecting Forebit" as one explanation. Those are forum accounts. We report them as such, and we do not adopt the interpretation as our own.
Sources: Shoplio DNS, whois and HTTP check, 18 September 2026 09:15 UTC · US Department of Justice press release, 30 January 2025 · BlackHatWorld thread, opened 2 August 2026
What sellers lost
Three things went at once. First, the storefronts: the platform hosts, including the APIs the hosted shops depended on, now serve nothing but the banner, and posters report their sales stopping with the outage. Second, the data: product catalogues, stock, order history and customer lists lived behind APIs that now serve the banner, so no export is possible after the fact; the sellers who could rebuild quickly were the ones holding their own copies. Third, the balances: posters report five- and six-figure sums held in platform wallets that they could no longer access. The individual amounts are self-reported and unverified; the pattern is consistent across the thread.
The needs sellers voiced afterwards are specific: funds that land in a wallet they control, automatic withdrawal of anything above a threshold so little sits on the platform, no forced migrations that move funds, data export at any time, and more than one payment gateway so a single failure is not fatal. A 2025 thread on the same forum had already added processor risk to the list, with reports of Stripe and PayPal account bans on some platforms.
Sources: BlackHatWorld thread, opened 2 August 2026 · same thread, page 2 · BlackHatWorld, March 2025
A checklist for choosing the next platform
1. Custody: where does a paid order go?
Ask whether a payment lands in an account you own (merchant-connected) or in a balance the platform holds (custodial). If it is custodial, ask whose keys sit behind the wallet and whether the platform can move funds between wallets without you. "Non-custodial" in marketing copy is not an answer; the August 2026 posters report that the wallets marketed that way were the ones whose funds moved.
2. Withdrawal cadence: how little can sit on the platform?
Look for an automatic withdrawal above a threshold you set, a low manual minimum, and per-network minimums you can live with. The exposure on a custodial platform is whatever sits there between sweeps, so the sweep interval and threshold are the number that matters.
3. Gateway redundancy: does checkout survive one processor failing?
A second crypto gateway you can switch to, or several merchant-connected processors, mean a single outage or account freeze does not have to end sales; ask whether the switch is automatic or something you do by hand. Sellers in 2025 also reported Stripe and PayPal account bans on some platforms; ask what happens to your checkout if one processor drops you.
4. Export and migration: can you leave?
Ask for product, order and customer export at any time, and check what the platform can import. An importer that reads a source API is useful only while that API is up; every API involved in the August 2026 event is now dark, and the sellers who kept their own product lists are the ones who could rebuild.
5. 2FA and staff controls: who can move money?
Check which actions carry a second factor (login, changing payout addresses, granting money access to team members), whether platform staff can create withdrawals while impersonating you, and whether team members with withdrawal access are logged and reported. Be precise: 2FA on login is not 2FA on every withdrawal, and a platform should tell you which it has.
The checklist applied to Shoplio
Since this guide is published by a platform, here is the same checklist applied to it, without softening. Custody: Shoplio is custodial. A paid order credits a balance held in the platform's gateway wallets (Cryptomus and OxaPay) until you withdraw; the balance is computed per currency and gateway as paid orders minus withdrawals. Withdrawal cadence: auto-withdrawal sweeps any balance above a USD threshold you set (from $10 to $1,000,000) to a wallet address per currency, with a ten-minute debounce and per-network minimums of $10 for BTC and $20 for ETH and ERC-20 tokens; the manual minimum is $1; GRAM is withdrawn manually only. Gateway redundancy: two crypto gateways are supported (Cryptomus and OxaPay), each with signed webhooks and a poller that catches missed confirmations, but a shop uses one at a time and the owner switches it by hand in Settings; checkout does not fail over automatically. Export and migration: the importer reads the Sellpass and Antistock APIs, both of which are offline, so it cannot import from them today, and there is no importer for the other platforms. 2FA and staff controls: email-code 2FA on login and on turning 2FA on or off; where team withdrawal access is enabled on the platform, granting it to a team admin also takes password plus code, with a cool-off delay, is revocable, and every co-owner withdrawal is reported to the owner and audited; there is no separate 2FA challenge on each withdrawal; withdrawals cannot be created and auto-withdrawal settings cannot be changed from an admin impersonation session. Fees: 5% on the Free plan and 3% on Pro and Enterprise, charged at withdrawal; no platform fee per order, though orders are credited net of the gateway's own commission.
The compare page lists every platform we checked, online and offline, with sources; the per-platform pages cover Billgang, Antistock, Sellpass, Sellix, Hoodpay and Forebit.