Pay attention to the signed content! Vercel is hit with ransomware demanding $2 million, and crypto protocol frontend security raises a red flag

FIL1,6%
COW1,92%
AERO10,1%

Cloud development platform Vercel was hacked on April 19. The attackers gained access by using a third-party AI tool used by employees, and are apparently selling the stolen data publicly on a forum, with an asking price as high as 2 million USD. Because many crypto projects deploy their wallet interfaces and dApp front ends on Vercel, the incident has also raised concerns across the crypto community.

Attack source: employee third-party AI tool OAuth compromised

In an official security bulletin, Vercel said that a Google Workspace OAuth application under Context.ai—the third-party AI tool used by an employee—was compromised. The attackers used it to hijack that employee’s Google Workspace account and then infiltrate Vercel’s internal data.

Vercel CEO Guillermo Rauch revealed in a post on X that the attack may affect hundreds of organizations that use the same tool, not just Vercel.

Rauch described the hackers’ attack plan as “highly sophisticated,” and suspects they used AI to significantly enhance the intrusion efforts, showing a deep understanding of Vercel’s internal architecture. At present, Google-owned cybersecurity firm Mandiant is assisting with the investigation, and Vercel has also notified relevant law enforcement agencies.

Members of hacking organization post to extort $2 million

Vercel said that sensitive data is stored in an encrypted form and was not accessed; however, other data not labeled as “sensitive” may have been read and used by the attackers.

A screenshot of a forum post circulating on Telegram

A person claiming to be associated with the hacking organization ShinyHunters posted on the cybercrime forum BreachForums, saying they had obtained Vercel’s API keys, NPM tokens, GitHub tokens, source code, and internal database contents, and released about 580 employees’ data as “proof” of a breach, including employees’ names, company email addresses, account statuses, and activity times.

ShinyHunters denies involvement; the truth behind the extortion negotiations is unclear

What’s hard to believe is that although the poster claimed to be from ShinyHunters, the organization has already publicly denied participating in this incident, leaving the attackers’ true identity shrouded in mystery.

The attackers also claimed they had contacted Vercel through Telegram and about the $2 million ransom, and demanded that 500k USD in Bitcoin be paid first to retrieve some of the data, but Vercel has not confirmed this.

Crypto agreements flash red: front-end supply chain becomes a new attack surface

The impact of the Vercel incident on the crypto space should not be underestimated. A large number of decentralized exchange (DEX) and wallet front-end interfaces, as well as dApp dashboards, are deployed on Vercel. If a relevant crypto project’s private RPC endpoints, third-party API keys, or wallet-related sensitive secrets are stored in data not labeled as “sensitive,” then this information could be leaked.

For context, a lot of DeFi is hosted on Vercel and crypto users are a prime target for such attack.

If you need to use DeFi in this time of crisis, verifying what you sign is of utmost importance! You can also use .eth.limo (just hacked but back up and running) or IPFS frontend…

— Pybast (@Pybast) April 19, 2026

In simple terms, attackers can theoretically directly tamper with a project’s website and interface, lure users into clicking and signing malicious contracts—not just redirecting a domain to a phishing website, fully bypassing monitoring and protection at the DNS layer. So far, there has been no reported incident involving any protocol, but security teams across the industry have already listed it as a potential severe risk.

In fact, front-end security issues in the crypto space have long been a persistent problem for the industry. Last week, DEX CoW Swap suspended trading due to a domain hijacking incident. Aerodrome and Velodrome were also hit by DNS hijacking attacks in November last year.

Vercel rolls out data updates, urging users to immediately replace their keys

Vercel said the company’s services are currently operating normally and the investigation is still ongoing, while also updating its data management dashboard. The company strongly recommends that all users immediately conduct a comprehensive review of existing data, replace keys for all data not labeled as “sensitive,” and enable the platform’s sensitive variables feature to ensure that related credentials are stored in an encrypted form.

This article pay attention to the signed content! Vercel hacked and extorted 2 million USD; front-end security warning lights up for crypto protocols first appeared on Chain News ABMedia.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

U.S. Military Confirms Bitcoin Node Operations as Multiple Nations Adopt Crypto for Statecraft

Gate News message, April 26 — Admiral Samuel Paparo, Jr., who leads U.S. forces across the Indo-Pacific, told a Senate panel that Bitcoin matters to national security. The Pentagon is running its own Bitcoin node and conducting operational tests to secure and protect networks using the Bitcoin

GateNews50m ago

U.S. Sanctions Iran-Linked Crypto Wallets, Tether Freezes $344 Million USDT

Gate News message, April 26 — The U.S. federal government sanctioned multiple wallets linked to Iran on April 25, with Treasury Secretary Scott Bessent announcing the action as part of efforts to increase economic pressure on the country amid an ongoing ceasefire. The sanctions came a day after

GateNews3h ago

Trump Says Iran Should Act Wisely, but U.S. Will Win Regardless

Gate News message, April 26 — In an interview on April 26, U.S. President Trump commented on the Iran situation, stating that America's greatest advantage is having destroyed Iran's navy and air force, with Iran's leadership now replaced. Trump noted that the current Iranian leadership is mixed—some

GateNews5h ago

Major Central Bank Decisions and Tech Earnings Set to Drive Markets Next Week

Gate News message, April 26 — Next week brings a super central bank week and earnings season, with the Federal Reserve, Bank of Japan, Bank of England, European Central Bank, and Bank of Canada all set to announce interest rate decisions. The Federal Reserve will release its rate decision at 2 a.m.

GateNews6h ago

Trump Urges UK PM to Restore Hormuz Strait Shipping as Iran Warns of Permanent Change

Gate News message, April 26 — U.S. President Donald Trump spoke with UK Prime Minister Keir Starmer to discuss the ongoing Middle East situation and emphasized the "urgent need to restore shipping through the Strait of Hormuz." Starmer noted that weeks of blockade have left numerous crew members st

GateNews6h ago

Vietnam to Launch First Regulated Crypto Trading Platform With 5-Year Pilot Program

Gate News message, April 26 — Vietnam's government plans to launch a five-year pilot program for regulated crypto assets in the second quarter of 2026, transitioning previously offshore and unregulated cryptocurrency trading to a domestically regulated market, according to BlockBeats. Vietnam's tra

GateNews8h ago
Comment
0/400
No comments