Hack at Vercel sends crypto developers scrambling to lock down API keys
Vercel said a limited subset of customers was affected as it investigates whether attackers exfiltrated access keys, source code and API keys.
- Cloud development platform Vercel disclosed a security incident after threat actors claiming to be "ShinyHunters" alleged they breached internal systems and accessed company data.
- The company traced the intrusion to a compromised Google Workspace connection within Context, a third-party AI tool used by an employee, allowing attackers to escalate access into internal environments.
- Attackers potentially accessed API keys and 580 employee records containing names and timestamps, while the threat actor alleged a $2 million ransom demand in Telegram messages.
- Solana-Based decentralized exchange Orca rotated all deployment credentials as a precaution, while Vercel advised customers to rotate secrets and use its sensitive environment variable feature.
- This incident adds to a difficult April for crypto, following a $292 million exploit of Kelp DAO and a $285 million attack on Drift linked to North Korea-affiliated actors.
45 Articles
45 Articles
Vercel Confirms Security Breach as Hacker Demands $2 Million and Claims to Sell Internal Access
Vercel, the cloud deployment platform that underpins frontend infrastructure for thousands of applications including many Web3 projects, confirmed a security breach on April 19 after a threat actor posted on BreachForums claiming to be selling stolen data for $2 million. The listing claimed to include access keys, source code, database content, and API tokens, including NPM and GitHub tokens tied to internal deployments and developer environment…
Next.js developer Vercel warns customer creds compromised
Blames outfit called Context.ai, which reckons an agentic OAuth tangle caused the incident Vercel, the company that created the open source Next.js web development framework, has a data leak that led to compromise of some customer credentials, and blamed an outfit called Context.ai for the mess.…
Vercel hacked, hacker using ShinyHunters name to sell data for $2 million
Vercel, a cloud platform that hosts and deploys web apps, was recently compromised in a cyberattack stemming from an AI tool. The company says that no sensitive data was accessed after hackers claimed to be selling Vercel customer data online. Vercel has clients such as OpenAI, Cursor, Bose, and Pinterest.
Coverage Details
Bias Distribution
- 78% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











