In early 2024, a Microsoft engineer named Andres Freund was doing routine performance profiling on a Debian system when he noticed something that shouldn’t exist: SSH logins were consuming about 500 milliseconds more CPU time than they should. He kept pulling the thread. What he found, buried inside a compression library called XZ Utils, was a meticulously crafted backdoor that had been planted over two years by a fake developer persona named Jia Tan.
Freund published his findings on March 29, 2024. The security community’s reaction oscillated between awe and horror. Awe at the sophistication of the attack. Horror at how close it came to working.
XZ Utils compresses and decompresses data. It is not glamorous software. It does not have a conference, a venture-backed company behind it, or a Slack community with thousands of members. For much of its existence, it was maintained by a single developer, Lasse Collin, who had been dealing with significant personal health problems. The project was understaffed in the way that most foundational open source software is understaffed: quietly, without anyone in particular noticing, because the software kept working.
That’s the setup. Here’s what happened.
Jia Tan first appeared in the XZ Utils issue tracker in 2021, submitting reasonable patches, behaving like a diligent contributor. Over two years, the persona cultivated trust methodically. Other accounts, likely sockpuppets, applied social pressure on Collin, suggesting he was too slow, that the project needed more help. Eventually Collin gave Jia Tan commit access. The backdoor was introduced in early 2024 and made it into beta versions of Fedora 40 and Fedora Rawhide, as well as some Debian and Kali Linux distributions, before Freund caught it.
The backdoor targeted systems running systemd and would have allowed anyone with the right private key to authenticate to SSH without credentials. On any server running the compromised package, a remote attacker could have gained root access silently. The attack was aimed squarely at the Linux servers running cloud infrastructure, financial systems, and government networks.
Freund found it by accident, because he was curious about a performance anomaly. There was no automated system that caught it. There was no bounty program that flagged it. There was no security team at an XZ Utils, Inc. doing code review. There was a Microsoft engineer who happened to be running Debian as a personal system and had the knowledge and the time to care.
This near miss is not an anomaly. It is a demonstration of how the system actually works.
Open source software forms the substrate of nearly all modern technology. The Linux kernel powers most cloud servers. OpenSSL secures most encrypted web traffic. curl handles HTTP requests in billions of devices. These projects exist in a peculiar economic position: they are extraordinarily valuable to the companies that depend on them and, in many cases, maintained by volunteers or small teams operating without sustainable funding.
The 2014 Heartbleed vulnerability in OpenSSL made this structural problem briefly visible. OpenSSL at the time was generating around $2,000 per year in donations. It was securing a substantial fraction of internet traffic. After Heartbleed, several large technology companies formed the Core Infrastructure Initiative to fund critical open source projects. Funding improved. The broader incentive problem did not.
What makes XZ Utils the sharper case study is the attack vector it reveals. The weakness was not in the code itself, not initially. It was in the social and economic conditions around the code. Collin was a single maintainer under personal strain. The project had no succession planning, no organizational structure, no paid staff. That vulnerability, the human one, was what Jia Tan exploited. Two years of patient relationship-building bought commit access to software running on millions of servers.
The economics of this situation are almost deliberately perverse. A company running a service on Linux, using XZ Utils to handle compression, contributes nothing to XZ Utils by default. The cost of that contribution is zero. The benefit of having XZ Utils maintained is enormous. Every company in that position faces the same calculation, and the rational individual move is to free-ride. The tragedy of the commons, applied to software.
Some funding mechanisms exist. The Open Source Security Foundation runs bug bounties and provides some funding. GitHub Sponsors and Open Collective allow direct donations. The Sovereign Tech Fund, backed by the German government, has been funding open source maintainers directly. These programs are real and meaningful. They are also nowhere near sufficient relative to the scale of critical infrastructure they’re trying to support.
The companies with the most to lose, large cloud providers and enterprise software vendors, have made some investments. Red Hat, now part of IBM, employs kernel contributors. Google funds certain security-critical projects. But these investments are often project-specific and motivated by direct business need rather than any systematic assessment of what the broader infrastructure requires. Projects with obvious commercial adjacency get funded. Projects that are merely essential do not.
The XZ Utils backdoor failed because one engineer was curious about 500 milliseconds. That is not a security posture. That is luck wearing the costume of competence.
What should change is not mysterious. Governments can fund critical open source infrastructure the way they fund physical infrastructure, because it is infrastructure. The EU’s Cyber Resilience Act is moving in this direction by requiring software vendors to demonstrate they’ve addressed security in their supply chains, which creates at least indirect pressure to fund the dependencies they rely on. Large enterprises can move from ad-hoc sponsorship to systematic audits of their software supply chains, identifying which dependencies are under-maintained and funding them proportionally to risk.
Maintainers can, where possible, be less reluctant to say no, to establish clearer governance, and to require organizational structure before granting commit access to new contributors, however patient and helpful they seem.
None of this is simple. The open source community has a complicated relationship with formalization, for understandable reasons. But the economic model that governs open source sustainability has a structural flaw that the XZ Utils case made visible in the starkest possible terms. The cost of maintaining foundational software is diffuse and mostly invisible. The cost of not maintaining it tends to arrive suddenly, at scale, and all at once.
Jia Tan’s operation reportedly began in 2021 and unraveled in 2024. Three years of investment by a sophisticated threat actor against a single volunteer-maintained library almost compromised the SSH authentication layer of the global internet. The attacker understood the economics of open source maintenance better than most of the companies depending on it did.