milw0rm▊
Days after India detonated five nuclear devices in the Rajasthan desert, a handful of teenagers who had never met in person — scattered across England, the Netherlands, New Zealand and the United States — walked into the network of India's flagship nuclear-weapons lab, hung a mushroom cloud on its homepage, and told the press they'd carried thousands of pages of the scientists' email out the door. Their oldest member was eighteen. Their stated cause was that nobody should be building bombs, and their proof-of-work was that the Bhabha Atomic Research Centre had left the front door open. India said nothing important was taken. The kids said otherwise. Nobody was ever arrested.
Read this first. There are two things called "milw0rm," and they are not the same. This file is about the 1998 anti-nuclear hacktivist CREW. It is not the later exploit-archive website milw0rm.com run by the researcher known as "str0ke" from roughly 2004 to 2009 — a completely separate operation that borrowed the name. As Wikipedia puts it flatly: "the exploit site milw0rm.com and str0ke are unaffiliated with the milw0rm hacker group." Nothing about the exploit site belongs to the kids in this file, and vice versa.
If a nuclear war does start, you will be the first to scream.
The milw0rm crew, on the mushroom-cloud message they left on the Bhabha Atomic Research Centre's defaced homepage, June 1998 — verbatim text preserved on Wikiquote, from Wired
- WHO
- milw0rm — an international teenage crew: JF (18, England), savec0re (17, Netherlands), VeNoMouS (18, New Zealand), Keystroke (16, US), ExtreemUK (England), and Hamst0r — united only over the internet FACT
- THE TARGET
- India's Bhabha Atomic Research Centre (BARC), Mumbai — the country's flagship nuclear-research lab, breached in early June 1998, days after the Pokhran-II weapons tests FACT
- THE MOTIVE
- Anti-nuclear protest — "I'm just sick of nuclear shit," one member told Wired. They defaced the site with a mushroom cloud and a peace message
- THE DISPUTE
- The crew claimed they downloaded thousands of pages of scientists' email and erased data on two servers ATTRIBUTED; BARC said nothing confidential was exposed ATTRIBUTED
- NOT TO BE CONFUSED WITH
- The later exploit-archive site milw0rm.com (str0ke, c. 2004–2009) — unaffiliated, a different thing entirely
- STATUS
- DISBANDED — the crew scattered after 1998; no arrests, no extraditions, members were juveniles across several jurisdictions
This file is not an accusation so much as a record of a strange moment: the week a nuclear state was embarrassed by children. The break-in and the defacement are documented — the crew gave on-the-record interviews and mailed the reporter files as proof. What sits in dispute is the scale: the kids said they walked out with the scientists' inbox and wiped servers on the way; BARC said nothing sensitive was ever at risk. Both claims are here, each attributed to who made it. The members were minors, no real names were ever established, and this file adds none.
the drama timeline
ACT I — THE DESERT AND THE DARE (May 1998)
India rejoins the nuclear club with five blasts under the Rajasthan sand. A few thousand miles away, a chat channel full of teenagers decides to make it personal.
-
MAY 11–13, 1998
Pokhran-II
India conducts a series of underground nuclear-weapons tests at the Pokhran range — the five blasts that would put the country back on the world's front pages and, weeks later, on milw0rm's target list. Wired's account of the hack fixes the crew's stated grievance to exactly these tests: "the five nuclear blasts that India conducted beginning 11 May."
-
1998
A crew that only existed online
milw0rm was, in Wired's phrase, "an international hacking team united only by the Internet" — teenagers who had never shared a room. The roster: JF, 18, England; savec0re, 17, the Netherlands; VeNoMouS, 18, New Zealand; Keystroke, 16, in the US; ExtreemUK, England; and Hamst0r. VeNoMouS told Wired he'd learned to crack from Ehud Tenenbaum — "Analyzer," the Israeli teenager caught up in the U.S. government intrusions earlier that year.
ACT II — THE BREAK-IN (early June 1998)
Through an old mail server and a borrowed military machine, the kids walk into a nuclear lab, take the homepage, and phone the press.
-
JUN 1–3, 1998
Root on the .barc.ernet.in domain
The crew broke into BARC's network — by their account, over a couple of days beginning that Monday. "We gained total control over six of the eight servers on the *.barc.ernet.in domain," savec0re told Wired. The crew said they'd gotten root through a then-fresh Sendmail vulnerability against an old, unpatched version of the mail program, and that JF had launched the attack by bouncing through a U.S. military .mil machine. "They had certain things secured to the bone, and yet other things were completely obsolete," savec0re said.
-
JUN 3, 1998
The mushroom cloud
The crew replaced BARC's homepage with a spoof page: a mushroom cloud over the line "If a nuclear war does start, you will be the first to scream ..." The full defacement, later preserved, ran the argument in scene-kid vernacular — "its not clever, its not big, so don't think destruction is cool, coz its not" — and signed off with the handles. By the time reporters looked, the webmaster had pulled the spoof and the site showed a bare directory listing.
-
JUN 3, 1998
The claim — and Wired's caveat
Over IRC, the crew told Wired they had "download[ed] several thousand pages of email and research before we decided it was time to get out," and that they had "erased all data on two of BARC's servers" as a protest. They emailed the reporter a batch of files — apparent nuclear-physics discussions dated as recently as that Monday — as proof. Wired printed the caveat in the same breath: the files' authenticity "was not confirmed," and BARC and the Indian Embassy had not responded. The claim of scale, in other words, was theirs; the confirmed part was the break-in and the defaced page.
ACT III — THE MASS HACK (July 1998)
One target wasn't enough. A month later the crew and its allies staged what the press called the largest mass defacement ever attempted.
-
JUL 1998
The Easyspace mass hack
A month after BARC, milw0rm — with the allied crew "Ashtray Lumberjacks" — hit the British web host Easyspace and pushed the same anti-nuclear mushroom-cloud message onto more than 300 hosted sites in under an hour. Wired called it perhaps "the largest 'mass hack' ever undertaken." The message widened from India to the whole standoff: "this could seriously escalate into a big conflict between India and Pakistan and possibly even World War III, and this CANNOT happen ... Use your power to keep the world in a state of PEACE."
ACT IV — THE AFTERMATH (late 1998–)
The story got big, the debate got serious, and the crew — being teenagers in five countries — simply drifted apart. And a name got recycled.
-
NOV 1998
BARC's answer — and the "100 hackers"
Forbes's long look-back, "Hacking Bhabha," gave BARC its say: the lab's position was that none of the exposed email held confidential information and that genuinely sensitive material was isolated from the internet-facing systems. The same reporting noted the uglier side of the crew going public — once BARC's servers were known to be soft, Forbes reported, perhaps up to 100 other intruders wandered in behind milw0rm. The debate the hack kicked off — hacktivism, nuclear secrecy, and how a nuclear power got embarrassed by kids — outlasted the crew itself.
-
1998–99
Disbanded, uncaught
There was no raid, no perp walk, no extradition fight. The members were juveniles spread across at least four countries, and the crew simply stopped — drifting out of hacktivism the way teenage crews do. That's the whole ending: a nuclear lab breached by children who then went back to being children, and a state that never laid a hand on any of them.
-
c. 2004–2009
The name gets recycled — a DIFFERENT milw0rm
Years later a well-known exploit-archive website, milw0rm.com, run by a researcher going by "str0ke," made the name famous a second time to a whole new generation. It is worth saying once more, plainly: that site has nothing to do with this crew. Same seven characters, unrelated people, unrelated project. "The exploit site milw0rm.com and str0ke are unaffiliated with the milw0rm hacker group." Don't let a search engine glue them together.
both sides, on the record
The lab's case: a break-in is a break-in, and defacing a national research center is trespass dressed up as protest. BARC's position was that the crew hit an internet-facing perimeter, not the crown jewels — nothing confidential was exposed, and the sensitive weapons work was isolated from the systems the kids reached. On that account the "we stole the nuclear inbox" headline was teenage theater over a soft public web server.
And the scale was self-reported: the most dramatic claims — thousands of pages carried off, servers wiped — came from the intruders themselves, over IRC, in an interview Wired openly flagged it could not verify. Treat unverified boasts as boasts.
The break-in was real, and so was the point: whatever the value of what they took, they demonstrably got root on a nuclear lab's network through an unpatched mail server and hung their message on its homepage — and mailed a reporter files as proof. The security failure they exposed was genuine, and by Forbes's account plenty of others walked in behind them [1] [3].
They asked for nothing: no ransom, no sale, no market. The stated aim was a protest against nuclear weapons — "I'm just sick of nuclear shit" — and the payload was a peace message, not a price. Whatever you make of the method, the motive was on the page [1].
They were kids, and everyone knew it: the oldest was eighteen. No court ever tested the "erased data" claim because no one was ever charged. Judge the deed; the archive isn't going to name or chase juveniles a quarter-century on [4].
YOU DECIDE
The confirmed record is remarkable enough without the boasts: a nuclear-weapons lab's network taken to root by teenagers on three continents, its homepage flying a mushroom cloud, all because someone left an ancient mail server on the internet. Whether they really carried out the scientists' inbox or wiped two servers is a claim they made and BARC denied, and no court ever settled it. Strip it to what's proven and you're left with the durable lesson of 1998: the perimeter of a nuclear state was soft enough for children to embarrass, and the loudest thing they stole was its dignity.
The archive keeps the defacement and the denial in the same drawer. It does not name the children.
evidence locker
CONTEMPORANEOUS PRESS (1998)
Wired — "Crackers: We Stole Nuke Data" (James Glave, 3 Jun 1998) ATTRIBUTED — the primary contemporaneous account: the crew's on-record IRC interview, the six-of-eight servers claim, the Sendmail/
.mil method, the mushroom-cloud spoof page, the "several thousand pages"/"erased all data" claims, and Wired's own caveat that the files' authenticity was not confirmed.
wired.com/1998/06/crackers-we-stole-nuke-data
Wired — "Anti-Nuke Cracker Strikes Again" (3 Jul 1998) ATTRIBUTED — the July Easyspace mass defacement (300+ sites in under an hour), "the largest 'mass hack' ever undertaken," and the widened India–Pakistan peace message; the source Wikiquote cites for the verbatim defacement text.
wired.com/1998/07/anti-nuke-cracker-strikes-again
Forbes — "Hacking Bhabha" (16 Nov 1998) ATTRIBUTED — long-form look-back: member ages and nationalities, BARC's downplaying (no confidential email exposed, sensitive data isolated), and the report that up to ~100 other intruders followed the crew in once BARC was known to be soft.
forbes.com/1998/11/16/feat.html
PRIMARY / REFERENCE
Wikipedia — milw0rm ATTRIBUTED — the crew's formation, roster, the BARC and Easyspace hacks, dispersal without arrests, and the explicit statement that "the exploit site milw0rm.com and str0ke are unaffiliated with the milw0rm hacker group."
en.wikipedia.org/wiki/Milw0rm
Wikiquote — milw0rm SELF-PUBLISHED — the verbatim text of the BARC defacement message and the group's slogan, with the Wired citation; the source for the "In their own words" line above.
en.wikiquote.org/wiki/Milw0rm
CONTEXT & CROSS-LINKS
troll.fan — The Morris Worm CROSS-LINK — the other file where a piece of code became a national-security story and the law had to catch up; the hacking-meets-geopolitics precedent.
troll.fan/dossiers/morris-worm.html
The standard. milw0rm's members were minors in 1998; no real names were ever publicly established and this file adds none — no dox, and the juvenile status is stated without moralizing. The break-in and the mushroom-cloud defacement are treated as fact, sourced to contemporaneous press and the crew's own on-the-record interview with Wired, who received email files as proof. Everything beyond that — thousands of pages downloaded, data erased, the "13 minutes" — is the crew's claim, attributed as such, and Wired's own caveat that the files' authenticity was unconfirmed is kept in view. BARC's position that nothing confidential was exposed is given, attributed to BARC. And the disambiguation runs throughout: this is the 1998 crew, not the later, unrelated exploit site milw0rm.com. If a line here couldn't survive scrutiny, it wouldn't be on the page.