todayonchain.com

Hack at Vercel sends crypto developers scrambling to lock down API keys

CoinDesk
Vercel suffered a security breach via a compromised AI tool, prompting crypto developers to rotate API keys and secure their applications.

Summary

Web infrastructure provider Vercel has disclosed a security breach linked to a compromised Google Workspace connection via the third-party AI tool Context.ai. The incident potentially exposed customer API keys, leading many crypto projects that host frontend interfaces on Vercel to rotate their credentials as a precautionary measure. While Vercel maintains that "sensitive" environment variables remain protected and there is no confirmed evidence of data exfiltration, the company is collaborating with incident response firms and law enforcement to investigate claims of stolen data circulating on a cybercrime forum.

(Source:CoinDesk)