Gate News message, April 23 — Vercel CEO Guillermo Rauch announced that the company has completed an in-depth security investigation spanning nearly 1 petabyte of complete Vercel network and API logs, extending well beyond the initial Context.ai account breach.
The investigation revealed that attackers operated on a broader scale than initially identified and have distributed malware across a wider range to steal account credentials from Vercel and other platforms. Once attackers obtain API keys, they systematically enumerate non-sensitive environment variables. Vercel has strengthened collaboration with industry partners including Microsoft, AWS, and Wiz to protect the broader internet ecosystem, and has notified other suspected victims with recommendations to rotate credentials immediately and implement security best practices.
Related News
RHEA Finance Security Incident Update: About a $400k shortfall remains, with a commitment to fully compensate it
Pay attention to the signed content! Vercel is hit with ransomware demanding $2 million, and crypto protocol frontend security raises a red flag
Context.ai hacked triggers a Vercel security crisis; the CEO publicly shares the full investigation progress