Vercel Breach Prompts Crypto Projects to Urgently Rotate API Keys
Vercel is a cloud platform widely used to host Web3 front ends, wallet interfaces and DEX dashboards. The supply-chain attack originated with third-party AI tool Context.ai. Hackers used its OAuth permissions to take over a Vercel employee’s Google Workspace account before moving laterally into internal systems. If deployment credentials were exposed, attackers could potentially tamper with front ends and induce users to sign malicious transactions.
Vercel disclosed the breach on April 19, 2026, and told customers to immediately rotate API keys, tokens, database credentials and signing credentials not marked as “sensitive.” Hackers claimed on BreachForums that they were selling access keys, source code and databases for $2 million. Orca promptly rotated all deployment credentials, and as of April 24, there was no evidence that its on-chain protocol or user funds had been compromised.
All Coverage
4 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.