Skip to content

Reselling and running a panel

Are nulled SMM panel scripts safe?

Last updated by The PanelCompare editorial team

Why is a panel script an unusually attractive backdoor target?

Because of what it holds. A panel stores provider API keys in plaintext by necessity — the API authenticates with a long-lived key sent in the request body, with no signing, no nonce and no timestamp, so there is nothing to hash and nothing to rotate automatically. It also holds every customer’s prepaid balance. One compromised installation yields both.

The keys are bearer secrets with no replay protection

Anyone holding a provider key can spend the balance behind it. That is a property of the API specification the whole market implements, not a flaw in any one panel — which is why where the script came from matters more here than in most software.

What does running one actually cost you?

  • Your provider balances, spendable by whoever holds the exfiltrated key.
  • Your customers’ wallet balances, which you are liable for whether or not you took them.
  • Your reputation, because the failure looks identical to an exit scam from the buyer’s seat.
  • Any hope of support. A cracked build cannot be patched by the vendor, and the known backdoors are not the interesting ones.

This is recorded in PanelCompare domain research (2026-09-06) as widely reported in operator forums rather than independently verified, and it is stated here as a risk rather than a measurement. The asymmetry is what settles it: the saving is bounded by a licence fee and the downside is not.

Think this answer is wrong?

Prices, refill terms and platform policies in this market all move, so an answer that was right in September may not be right in December. Every figure above names its source and the date it was checked; if one of them is stale or wrong, the correction process on the about page has a two-working-day reply target, and corrections are published with a dated note rather than quietly patched.