Quick Facts
- Vercel disclosed a security breach on April 19, 2026, traced to compromised Google Workspace connection via AI tool Context.ai
- Attackers accessed non-sensitive environment variables containing API keys and database credentials for limited number of customers
- Threat actor claiming to be ShinyHunters posted stolen data for sale at $2 million on hacking forums
Vercel confirmed a security breach that exposed internal systems and non-sensitive environment variables through a compromised third-party AI tool. The cloud development platform traced the attack to Context.ai, an AI platform used by a Vercel employee.
The attack began with a compromised Google Workspace OAuth application belonging to Context.ai. Attackers escalated access through the employee’s Google Workspace account into Vercel’s internal environments. They accessed environment variables not marked as sensitive, which contained API keys and database credentials.
Limited Customer Impact
CEO Guillermo Rauch confirmed that only a limited number of customers were affected. Vercel has contacted these customers directly and urged immediate credential rotation. Environment variables marked as sensitive remained encrypted and protected.
“We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI,” Rauch said. He noted the attackers moved with “surprising velocity and in-depth understanding of Vercel.”
Crypto Industry Concerns
The breach draws particular attention from the crypto industry. Many Web3 teams use Vercel to host wallet interfaces and front-end dashboards. Solana-based decentralized exchange Orca confirmed its frontend is hosted on Vercel and has rotated all deployment credentials as a precaution.
A threat actor claiming to be ShinyHunters posted on hacking forums offering to sell company data for $2 million. The data allegedly includes access keys, source code, database information, and API keys. However, threat actors linked to recent ShinyHunters attacks have denied involvement.
Company Response
Vercel has engaged Mandiant and additional cybersecurity firms. The company has also notified law enforcement and is actively investigating with Context.ai. Vercel rolled out dashboard updates including improved environment variable management interfaces.
The company maintains a strong financial position with $200 million in annual recurring revenue and a $9.3 billion valuation from its September 2025 funding round. Vercel stewards the Next.js framework, which records six million weekly downloads.
Customers are advised to review activity logs for suspicious actions and rotate environment variables containing sensitive data if not previously marked as secure.
Read more: Cloud development platform Vercel was hacked
