Articles
Crypto Market Analysis

Cloud hosting firm Vercel confirms ‘limited’ hack of user info

User Image

โดย ไม่ระบุชื่อ

สร้างแล้ว April 20, 2026|อ่านใน 2 นาที
Main Image

Vercel has confirmed it was compromised after a member of a hacking forum put the company’s information up for sale for $2 million.

Vercel, a cloud hosting provider popular among crypto projects, has confirmed that it suffered a security breach that allowed hackers to make off with a “limited” subset of customer credentials.

Vercel said in a blog post on Sunday that it “identified a security incident that involved unauthorized access to certain internal Vercel systems” and was investigating the breach.

“Initially we identified a limited subset of customers whose Vercel credentials were compromised,” it added. “We reached out to that subset and recommended an immediate rotation of credentials.”

Vercel’s confirmation came after multiple X users reported that a post on the hacking forum BreachForums by a user called “ShinyHunters” claimed to be offering Vercel’s data in exchange for $2 million.

The poster claimed to have access keys, source code, database information and employee accounts with access to internal deployments, which they said could be used for a “global supply chain attack.”

Vercel did not address the post’s claims, but said the attacker was “highly sophisticated based on their operational velocity and detailed understanding of Vercel's systems.”

Vercel CEO Guillermo Rauch said on Sunday that the attack originated after a Vercel employee was compromised via a breach of an artificial intelligence tool they used called Context.ai.

The attacker was then able to compromise the Vercel employee’s Google Workspace account, allowing them access to some of Vercel’s internal systems.

Rauch said the company stores customer environments with full encryption, but it has the capability to designate variables as “non-sensitive,” and the attacker “got further access through their enumeration.”

Related: Aave's TVL tanks $8B a day after $293M Kelp DAO hack

“We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI,” he added. “They moved with surprising velocity and in-depth understanding of Vercel.”

Rauch said that Vercel had “deployed extensive protection measures and monitoring” and it had analyzed its supply chain to ensure “Next.js, Turbopack, and our many open source projects remain safe for our community.”

“My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature,” he added.

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Source: CoinTelegraph


บทความอื่นๆที่เผยแพร่เมื่อเร็วๆนี้

Coinbase is testing AI agents that show up on Slack and email
Coinbase is testing AI agents that show up on Slack and email

Crypto Market Analysis

Brian Armstrong has now predicted that AI agents will not only transact onchain more than humans but...

Saylor teases 'bigger' BTC buy days after floating semi-monthly dividends
Saylor teases 'bigger' BTC buy days after floating semi-monthly dividends

Bitcoin

Strategy’s Michael Saylor posted “Think Even Bigger” on Sunday, coming just a week after it di...

BIS warns dollar stablecoins could strain banks and policy
BIS warns dollar stablecoins could strain banks and policy

Crypto Market Analysis

BIS general manager Pablo Hernández de Cos says US dollar stablecoins could pose risks to financial...

BTC price due 'new highs:' Five things to know in Bitcoin this week
BTC price due 'new highs:' Five things to know in Bitcoin this week

Bitcoin

Bitcoin saw a green weekly close despite renewed US-Iran war momentum, and a trader forecast that BT...

How Mastercard plans to settle card payments with stablecoins
How Mastercard plans to settle card payments with stablecoins

Blockchain

Mastercard is testing stablecoin settlement with SoFiUSD to speed up card transaction clearing and h...

LayerZero says Kelp setup caused exploit, as Aave loss questions mount
LayerZero says Kelp setup caused exploit, as Aave loss questions mount

Crypto Market Analysis

LayerZero said that Kelp’s DVN setup caused the $290 million exploit, as investors questioned whic...