Bambu Lab explains why it acted against a specific OrcaSlicer fork that impersonated its official client on cloud servers.
What This Controversy Is — and Isn't — About
Bambu Lab published an official statement on May 7, 2026, addressing widespread media coverage of its dispute with a particular OrcaSlicer fork. The company was clear: this situation has nothing to do with OrcaSlicer itself, its hundreds of legitimate forks, or the freedom to modify open-source code. The core issue is the protection of Bambu Lab's private cloud infrastructure.
Open-Source Code vs. Cloud Access: A Critical Distinction
Bambu Studio is licensed under AGPL-3.0, meaning anyone can freely take, modify, and redistribute its code — and over 700 forks already do so without issue. However, Bambu Lab draws a firm line between code licensing and access to its cloud services. The cloud is a private platform governed by a user agreement, not by the AGPL license.
The Technical Problem: Client Impersonation
The specific modification at the center of this dispute worked by injecting falsified identity metadata into network communications, making the unofficial fork appear to Bambu Lab's servers as the official Bambu Studio client — complete with a hardcoded version number. This kind of spoofing creates a structural vulnerability: if widely adopted, it could send thousands of indistinguishable requests to Bambu's servers simultaneously, risking outages that affect all users. Bambu Lab states it has already documented service disruptions caused by spikes in unauthorized traffic.
Alternatives for Advanced Users
Bambu Lab reminds users who prefer not to rely on cloud connectivity that LAN Mode, Developer Mode, and Bambu Connect are all available options. The company also runs an active Bug Bounty Program for responsible disclosure of security findings.
Bambu Lab's Bottom Line
Bambu Lab reaffirms its support for the open-source community and will continue contributing through Bambu Studio. What it will not permit is the impersonation of its official client in communications with its cloud infrastructure, citing the real risk to service stability for all users.



