Zeabur Pledges Compensation After API Keys Exposed in Breach
Taiwan-based cloud deployment platform Zeabur lets developers host applications and store credentials such as OpenAI and Anthropic API keys and database passwords in environment variables. Exposure of those secrets can allow attackers to impersonate users, access data and run up unauthorized charges, making the incident a direct financial and supply-chain security risk rather than a conventional data leak. Zeabur said some customers’ AI keys had already been abused.
Zeabur said the attacker gained access using a leaked, highly privileged Amazon Web Services credential, exposing environment variables from some customer projects. As of Aug. 31, the company had verified 63% of compensation claims, though it had not disclosed the total losses. Founder Mars Lin apologized and pledged reimbursement after claims are validated, while related AI Hub services were suspended as a precaution. Zeabur urged affected users to rotate credentials and review usage bills, and said it had found no evidence supporting a hacker’s claim of stealing 612 GB of internal data.
All Coverage
9 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →