A security compromise at infrastructure provider Vercel has exposed internal settings, prompting crypto projects to secure their API credentials. The breach originated from a third-party AI tool, raising concerns over supply chain vulnerabilities in the Web3 ecosystem.
- Vercel breach potentially exposed API keys used to connect apps to databases and wallets
- Attack originated from a compromised Google Workspace connection via third-party tool Context.ai
- Unverified claims on BreachForums suggest data is being sold for $2 million
- Vercel states 'sensitive' environment variables were not accessed
- Web3 projects, including Orca, are rotating credentials to mitigate risk
Sign up free to read the full analysis
Create a free account to unlock full AI-curated market articles, personalized alerts, and more.