Vercel CEO Reports Broader Malware Distribution Following Security Investigation, API Keys Targeted

Gate News message, April 23 — Vercel CEO Guillermo Rauch announced that the company has completed an in-depth security investigation spanning nearly 1 petabyte of complete Vercel network and API logs, extending well beyond the initial Context.ai account breach.

The investigation revealed that attackers operated on a broader scale than initially identified and have distributed malware across a wider range to steal account credentials from Vercel and other platforms. Once attackers obtain API keys, they systematically enumerate non-sensitive environment variables. Vercel has strengthened collaboration with industry partners including Microsoft, AWS, and Wiz to protect the broader internet ecosystem, and has notified other suspected victims with recommendations to rotate credentials immediately and implement security best practices.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

KelpDAO Advances on Recovery Plan, Prioritizes User Protection

Gate News message, April 23 — KelpDAO announced it is actively advancing a recovery solution following a recent security incident, with discussions progressing in a positive direction over the past few days. The project emphasized its core principle of "user first," stating that all subsequent

GateNews58m ago

Aave Sees $15.1B Deposit Outflow in 3.5 Days After KelpDAO Exploit, Stani Kulechov Outlines Recovery Efforts

Gate News message, April 23 — Aave founder Stani Kulechov outlined coordinated recovery efforts on April 22 following the KelpDAO incident, stating that the platform's priority remains protecting users and achieving orderly market conditions. He noted that teams have been working continuously with m

GateNews1h ago

Peter Schiff calls the Strategy STRC a Ponzi scheme, criticizing the SEC for inadequate regulation

Bitcoin critics and gold supporter Peter Schiff posted on X on April 23, saying that the STRC perpetual preferred stock introduced by MicroStrategy (Strategy) is “the most obvious Ponzi scheme to date,” and criticizing the U.S. Securities and Exchange Commission (SEC) for failing to effectively stop Michael Saylor from promoting STRC.

MarketWhisper2h ago

China Investment Guarantee Issues Statement Denying Unauthorized Use of Name in Fake Financial Products

Gate News message, April 23 — China Investment Guarantee (CITIC Guarantee) issued a statement on April 23 clarifying that unauthorized individuals have falsely claimed the company is partnering with Nippon Life India Asset Management (Singapore) Pte. Ltd., commonly known as NAMS, and is

GateNews3h ago

Crypto Hacks Fuel Wall Street Tokenization Debate

High-profile crypto exploits test DeFi risk yet unlikely derail tokenization; institutions favor permissioned chains, while broader tokenization must interoperate with DeFi; stablecoins face scrutiny and possible regulatory backlash.

CryptoFrontier14h ago

Volo Protocol Loses $3.5M in Sui Hack, Commits to Absorb Losses and Freeze Hacker Funds

Gate News message, April 22 — Volo Protocol, a yield vault operator on Sui, announced yesterday (April 21) that it has begun freezing stolen assets following a $3.5 million exploit. Hackers looted WBTC, XAUm, and USDG from Volo Vaults, marking the latest major DeFi security breach in a

GateNews17h ago
Comment
0/400
No comments