Sekoia alleges Exvicy ClickFix framework borrows code from rival ErrTraffic
Sekoia, a cybersecurity consultancy, has publicly asserted that the newly launched Exvicy ClickFix platform incorporates significant portions of source code originally written for the competing ErrTraffic service. The claim, first reported by Infosecurity Magazine, raises questions about intellectual‑property practices in the fast‑moving Managed‑as‑a‑Service (MaaS) market for web‑traffic protection.
Exvicy ClickFix is being marketed as a next‑generation solution for detecting and mitigating malicious click fraud, automated bots, and other forms of unwanted traffic that can inflate advertising costs and degrade site performance. The framework is positioned as a plug‑and‑play offering that integrates with existing ad‑tech stacks, promising real‑time analytics and automated remediation without the need for extensive in‑house engineering.
ErrTraffic, a well‑established player in the same niche, has built its reputation on a proprietary detection engine that blends machine‑learning models with heuristic rules. According to Sekoia’s analysis, several modules within Exvicy’s codebase mirror ErrTraffic’s architecture, including identical naming conventions, data‑flow patterns, and even specific comment blocks that appear unchanged from the original source. While code reuse is not unheard of in open‑source ecosystems, the alleged copying involves proprietary components that were never released under an open licence.
The allegation has sparked a debate among industry observers about the boundaries of acceptable reuse. On one hand, developers often draw inspiration from competitors, and certain algorithms may be considered industry standards. On the other hand, outright duplication of protected code can constitute copyright infringement and breach of trade‑secret protections, potentially exposing Exvicy’s backers to legal action. Neither Exvicy nor its parent company has responded to requests for comment at the time of writing.
If the claims hold merit, the repercussions could extend beyond a courtroom dispute. Clients who have already adopted ClickFix may face uncertainty regarding the reliability and legality of the service, while competitors could leverage the controversy to reinforce their own differentiation strategies. For the broader cybersecurity community, the case underscores the need for clearer guidelines around code provenance in commercial MaaS offerings.
Going forward, Sekoia says it will continue to monitor the situation and is prepared to assist affected parties in assessing any potential exposure. Industry analysts anticipate that the dispute could prompt a wave of due‑diligence checks among vendors, as buyers increasingly scrutinize the origins of the software that underpins their security operations. Until definitive legal findings emerge, the Exvicy‑ErrTraffic saga serves as a cautionary tale about the fine line between innovation and infringement in a sector where rapid development is prized above all.
Comments (0)
Be the first to comment.
Join the discussion