NO, IT’S NOT A SESSION STEALER
DonutFlipper reads market prices and shows them in your game. That’s it. It never touches your account and never sends anything about you anywhere.
A session stealer
- Grabs your login token
- Sends it to a stranger’s server
- They’re now in your account
DonutFlipper
- Asks donutflipper.com for prices
- Draws them on your screen
- Sends nothing about you at all
One place only
It only ever talks to donutflipper.com, over a secure connection.
Nothing about you
No login, no name, no location, no chat — ever leaves your PC.
Open to check
It’s a normal mod. Anyone can open it up and see for themselves.
YOUR SCANNER FLAGGED THESE?
Good — those are the right lines to look at. Here is exactly what each one is:
getAccessTokenflagged “dangerous”Your login goes to Mojang to prove it’s you, then straight back — never to us. It’s the same check that runs every time you join any server.
HttpClient, HttpClient$Builderflagged “network”How the mod asks donutflipper.com for prices. Every mod that loads anything online uses this.
"homepage": donutflipper.comflagged “external url”Just the mod’s website, written in its info file. A link, not code that runs.
Base64$Decoderflagged “encoding”Reads the signature on an update to check it is really from us before installing it. This flag is a safety feature.
ProcessBuilder, Redirectflagged “process”The auto-updater. It restarts the game’s own Java to swap in the new file — after the signature above checked out. No downloads are run, no commands, only our own jar.
Every one of these is in Minecraft and Fabric themselves. A scanner strict enough to flag them flags the game it’s running on — which is why a flag means “look here,” not “it’s a virus.”
THE ONE REAL DANGER
Someone made a fake virus using our name. It is not our mod — it is different software with our name on the file. So the golden rule:
Only ever download from donutflipper.com/mod.
Never from a DM, a mirror, or an “installer.” We don’t do those. If you already ran a fake, change your Microsoft password and sign out of all devices.
Show me the proof — the actual code, for the technical
The mod’s only outbound request. A plain request for prices — no name, no coordinates, no chat, no token:
HttpRequest.newBuilder(URI.create("https://api.donutflipper.com/public/metas"))
.header("User-Agent", "DonutFlipperMod/" + version)
.GET()
.build();“But it uses my login once.” Only for the optional account feature, and only the way joining any server does — the standard Minecraft join handshake:
client.services().sessionService()
.joinServer(profileId, accessToken, challenge);
// The token goes to Mojang's own service and nowhere else.Mojang then tells our server “yes, that account is real.” We never receive the token, never store it, never see it. A thief sends your token to themselves; we ask Mojang to vouch for you. Opposite direction.
Check it yourself.
- Decompile the jar (any Fabric mod is public) — you will find one host, over HTTPS.
- Watch its traffic with a proxy or your firewall log — only donutflipper.com.
- Bring the exact flagged line to our Discord and we will explain what it does.
Still unsure? That’s fair — it’s your account. Ask us in Discord and we’ll walk you through it.