Is Whonix compromised/under attack?

Hello. I have become suspicious of a potentially successful attack on Whonix that happened today. There have been weird things happening to Whonix to me, and apparently to other users as I’ve seen in recent forum posts here and on the Kicksecure and Whonix forums.

I was in the middle of fresh installing Qubes yesterday and I had some issues where sdwdate wouldn’t update the time properly and I was unable to update the whonix templates.

I tried again today and, as other users reported as well, I got an error about an expired release file, as also reported here: Unable to update: release file is expired .

The issue seemed to have been fixed a few hours later and now, after reinstalling (so the system was as fresh as it could be; I also re-verified that the USB drive’s contents were had a good GPG signature on another Qubes system, and they did), when trying to update the whonix-gateway template, I had a signature verification failure for a debian fasttrack repository (which by the way doesn’t even seem to be enabled on my other Qubes machine) and, before I could tell what was happening, the update completely shut down along with the template VM, mid-update, no error. This really spooked me.

To rehearse: When updating on a totally fresh Qubes OS R4.3.1 install, the whonix gateway template reported in the initial logs a failed checksum error for a debian fasttrack repo, then it continued to update (also weird? shouldn’t apt stop the update in these cases?) and, between a download and another, the template shut down on its own without me even touching the computer. And no, I did not run out of ram.

I would happily provide logs of the failed update, if it wasn’t that the log files for apt and dpkg were completely empty on the whonix gateway VM. Also very weird.

I’m pretty spooked right now and also I’m worried that my other Qubes OS machine might be compromised, although it seems not to be showing any signs of it at the moment of writing and the update process of whonix finishes normally, reporting no new updates and not even mentioning in the log a fasttrack repo, let alone a failed checksum verification error.

How exactly do you see a machine compromised via whonix?