Hello Hackers!
Version 0.4.1 is live. This is the largest update to How To Hack In? so far, bringing months of work together into a much more connected hacking sandbox.
NPC now have routines, personalities, relationships, and conflicts. Companies have suppliers, clients, repositories, infrastructure, and economic health. Intelligence gathered in one place can unlock a completely different route into an operation. Passive trace is also finally introduced - you can get caught after you disconnect if you leave enough evidence behind.
Important: version 0.4.1 requires a new game
Saves created in version 0.3.8 or earlier are not compatible with 0.4.1.
This update changes the foundations of generated people, companies, relationships, services, repositories, the economy, progression, and other connected world data. Those old worlds cannot be migrated safely, so 0.4.1 will reject them instead of risking a partially broken game. Please start a new game and generate a fresh world after updating. Sorry for the inconvenience!

A world that lives
The generated world is no longer just a collection of targets. NPCs perform autonomous actions, maintain relationships, create files, publish social activity and blogs, move money, cooperate, compete, warn allies, and sometimes sabotage rivals. Their personalities affect security behavior, investigation speed, loyalty, curiosity, and how they respond when you approach them.
The new Profiler turns discoveries from websites, social profiles, messages, files, transactions, and hacked computers into connected dossiers. Map a target's relationships, identify useful hooks, follow assets back to their owners, and decide whether the best route is technical, social, or both.
The Social Engineering Toolkit gives you five approaches: phishing, vishing, pretexting, leverage, and bribery. Available options and success chances depend on what you know, what you ask for, and who you are targeting. The system will be even more improved and polished in the next updates.

Passive trace
The Passive Trace system makes operational security matter after the terminal session is over. Evidence left in logs can start an investigation that moves through four stages: Suspicious, Investigating, Traced, and Reported. Related machines can share evidence, turning one careless intrusion into a wider investigation.
Use the new Threat Monitor to follow active investigations, clean the relevant logs before a case is reported, or use Bounce Relay to route connections through compromised machines and mask your origin in remote logs. Early missions include a grace period before the full system activates, giving you time to learn the basics.

Web vulnerabilities, repositories, and software supply chains
Websites can now contain distinct, playable vulnerability classes rather than serving only as information pages. Discover and exploit default credentials, SQL injection, path traversal, upload bypasses, and IDOR.
The new git.hthi code host connects repositories to the companies and machines that depend on them. Search public code and commit history, uncover leaked access, publish a malicious release, and follow its rollout through the supply chain. Implant payloads can enroll selected machines into an active command-and-control listener, while Vulnerability Regression payloads can reintroduce an exploitable release. Pinned dependencies may dodge the update, so a campaign still needs planning.
You can rent a Basic SSH server or a Pro server with FTP, SCP, HTTP, and custom-domain web hosting. The C&C app is available as a core tool, while active listeners require a Pro rental. Standard and Encrypted compiler licenses let you generate listener-bound RAT files inside C&C; encryption changes detection risk, but it does not make an agent invisible. Company web content can also be edited directly through files stored on compromised machines.

Follow the money - or create the crisis
Companies now have suppliers, clients, competitors, changing health, and events that can affect their stock. A security incident or disrupted supplier can spread beyond the first target, creating both consequences and opportunities.
Version 0.4.1 also adds a connected cryptocurrency economy with a Wallet, Exchange, and Blockchain Explorer. Follow transaction histories, trace suspicious transfers, receive mission rewards in crypto, and use ShadowBay to buy or sell intelligence, hooks, and recovered artifacts through its escrow system.
Scams have also grown into a larger set of systems. You can fall victim to fraud, investigate and report a scam, help recover stolen funds, or cross the line and take over an operation yourself.

Find your own way
The new Skill Tree contains many skills across different categories: Technical Exploitation, Social Engineering, Network Operations, Intelligence & OSINT, Financial Operations, and Stealth & Evasion. Gain experience, and upgrade your techniques.
Visual Scripting lets you build repeatable operations on a node-based canvas. Combine commands, variables, conditions, loops, waits, retries, parallel branches, and sub-scripts, then watch the workflow execute inside the game. Templates and findable scripts give you places to start before you design your own.
The workstation has also received saved window configurations, shortcut overrides, persistent free-form desktop icon placement, reorderable taskbar icons, built-in themes, window animations, improved virtual-desktop workflows, and many smaller usability and performance improvements.

Academy: useful guidance first
The Academy opens in 0.4.1 with 12 playable interactive lessons. Playable lessons can require earlier lessons, progression, or ownership of the tool they teach, so they are not all available on a brand-new profile. The initial tour, Wiki, Guided Mode, and Hackopilot have also been updated to introduce the new systems and point players toward relevant in-game help.
Detailed 0.4.1 changelog
Added
Passive Trace investigations with Suspicious, Investigating, Traced, and Reported stages, post-disconnect progression, and cross-machine cascades.
Threat Monitor app and terminal command for tracking active investigations.
Bounce Relay command and visual route builder for multi-hop connections.
NPC personalities, autonomous routines, relationships, conflicts, warnings, rivalries, and world activity.
Profiler dossiers, assets, hooks, conflicts, and relationship graphs.
Social Engineering Toolkit with phishing, vishing, pretexting, leverage, and bribery.
Skill Tree with 48 skills across six gameplay branches and additional non-mission XP sources.
Dynamic company health, events, suppliers, clients, competitors, stock effects, and company-focused mission routes.
git.hthi repositories, leaked access paths, immutable releases, two malicious payload types, and scheduled downstream propagation.
Command-and-control listeners, remote agents, RAT access, and detection trade-offs.
Five in-browser vulnerability classes: default credentials, SQL injection, path traversal, upload bypass, and IDOR.
Version-aware MetaExploits that respect the software release installed on a target, including patched states.
Cryptocurrency Wallet, Exchange, Blockchain Explorer, NPC transactions, and crypto-connected missions.
ShadowBay purchasing, selling, escrow settlement, and delivery of intelligence, hooks, and recovered artifacts.
Visual Scripting with executable flows, variables, conditions, loops, waits, retries, parallel branches, sub-scripts, templates, and recovered scripts.
Editable company websites, rentable servers, custom-domain web hosting, and hosted NPC blogs.
Expanded scam victim, investigation, recovery, enforcement, and operator systems.
StegCrack for discovering data hidden in image files.
Generated public world signals (simulation outside of missions), NPC blogs, economy news, and activity tied back to the simulated world.
Changed and improved
Mission generation now uses company relationships, NPC traits, security, and world context when selecting targets and routes.
Company names better reflect their industries, while generated filenames better match their contents.
The initial tour, Wiki, Guided Mode, Hackopilot, Shop descriptions, web pages have been refreshed for 0.4.1.
In-game Academy to get players up-to-speed.
Added saved window configurations, customizable shortcuts, persistent free-form desktop icon placement, reorderable taskbar icons, built-in themes, window animations, and additional desktop personalization.
Taskbar right-click and Shift+F10 actions can open an existing window or create a new instance where the app supports it.
Various performance optimizations: Improved terminal history and command workflows, browser behavior, Shop purchases, app refreshes, and desktop responsiveness. Reduced unnecessary background refresh work across several apps and world systems.
Updated and expanded many in-game websites and generated content pools.
Fixed
Police fines now refresh the player's balance and state immediately.
Tor Browser marketplace pages now show fresh data after purchasing access or individual items.
New and replacement Tor Browser tabs now open the correct default Hidden Wiki page.
The exif command no longer leaves the terminal stuck when used on a non-image files
Chatter now refreshes correctly after NPC activity.
Thank you
0.4.1 is a major foundation for the kind of hacking simulated sandbox world I want How To Hack In? to become. While the current loop of missions is still central point, it's definitely going to change and more focus put on the emergent situations and dynamic gameplay instead of following missions to missions.
I know it again took longer than I wished to release this update - thank you for your patience.