Pay attention to the signed content! Vercel is hit with ransomware demanding $2 million, and crypto protocol frontend security raises a red flag

DEFI-0,85%
FIL-0,08%
COW-0,27%
AERO1,19%

Cloud development platform Vercel was hacked on April 19. The attackers gained access by using a third-party AI tool used by employees, and are apparently selling the stolen data publicly on a forum, with an asking price as high as 2 million USD. Because many crypto projects deploy their wallet interfaces and dApp front ends on Vercel, the incident has also raised concerns across the crypto community.

Attack source: employee third-party AI tool OAuth compromised

In an official security bulletin, Vercel said that a Google Workspace OAuth application under Context.ai—the third-party AI tool used by an employee—was compromised. The attackers used it to hijack that employee’s Google Workspace account and then infiltrate Vercel’s internal data.

Vercel CEO Guillermo Rauch revealed in a post on X that the attack may affect hundreds of organizations that use the same tool, not just Vercel.

Rauch described the hackers’ attack plan as “highly sophisticated,” and suspects they used AI to significantly enhance the intrusion efforts, showing a deep understanding of Vercel’s internal architecture. At present, Google-owned cybersecurity firm Mandiant is assisting with the investigation, and Vercel has also notified relevant law enforcement agencies.

Members of hacking organization post to extort $2 million

Vercel said that sensitive data is stored in an encrypted form and was not accessed; however, other data not labeled as “sensitive” may have been read and used by the attackers.

A screenshot of a forum post circulating on Telegram

A person claiming to be associated with the hacking organization ShinyHunters posted on the cybercrime forum BreachForums, saying they had obtained Vercel’s API keys, NPM tokens, GitHub tokens, source code, and internal database contents, and released about 580 employees’ data as “proof” of a breach, including employees’ names, company email addresses, account statuses, and activity times.

ShinyHunters denies involvement; the truth behind the extortion negotiations is unclear

What’s hard to believe is that although the poster claimed to be from ShinyHunters, the organization has already publicly denied participating in this incident, leaving the attackers’ true identity shrouded in mystery.

The attackers also claimed they had contacted Vercel through Telegram and about the $2 million ransom, and demanded that 500k USD in Bitcoin be paid first to retrieve some of the data, but Vercel has not confirmed this.

Crypto agreements flash red: front-end supply chain becomes a new attack surface

The impact of the Vercel incident on the crypto space should not be underestimated. A large number of decentralized exchange (DEX) and wallet front-end interfaces, as well as dApp dashboards, are deployed on Vercel. If a relevant crypto project’s private RPC endpoints, third-party API keys, or wallet-related sensitive secrets are stored in data not labeled as “sensitive,” then this information could be leaked.

For context, a lot of DeFi is hosted on Vercel and crypto users are a prime target for such attack.

If you need to use DeFi in this time of crisis, verifying what you sign is of utmost importance! You can also use .eth.limo (just hacked but back up and running) or IPFS frontend…

— Pybast (@Pybast) April 19, 2026

In simple terms, attackers can theoretically directly tamper with a project’s website and interface, lure users into clicking and signing malicious contracts—not just redirecting a domain to a phishing website, fully bypassing monitoring and protection at the DNS layer. So far, there has been no reported incident involving any protocol, but security teams across the industry have already listed it as a potential severe risk.

In fact, front-end security issues in the crypto space have long been a persistent problem for the industry. Last week, DEX CoW Swap suspended trading due to a domain hijacking incident. Aerodrome and Velodrome were also hit by DNS hijacking attacks in November last year.

Vercel rolls out data updates, urging users to immediately replace their keys

Vercel said the company’s services are currently operating normally and the investigation is still ongoing, while also updating its data management dashboard. The company strongly recommends that all users immediately conduct a comprehensive review of existing data, replace keys for all data not labeled as “sensitive,” and enable the platform’s sensitive variables feature to ensure that related credentials are stored in an encrypted form.

This article pay attention to the signed content! Vercel hacked and extorted 2 million USD; front-end security warning lights up for crypto protocols first appeared on Chain News ABMedia.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Strait of Hormuz Daily Transit Hits New Low at Just 3 Vessels

A report by UK's Vimeo reveals that only 3 vessels passed through the Strait of Hormuz on April 19, setting a new low for recent transit levels.

GateNews1h ago

Bitcoin returns to $76k, and Trump is willing to “directly” negotiate with Iran’s leaders

After experiencing sharp volatility over the weekend triggered by heightened U.S.-Iran tensions, Bitcoin returned near $76,000 on April 21. U.S. President Trump said that any agreement that Iran and the U.S. are currently negotiating will be “better than” the 2015 Joint Comprehensive Plan of Action (JCPOA), and that he is willing to meet directly with Iran’s leadership. The remarks briefly boosted market sentiment. However, Brent crude oil continued to swing around $90 per barrel, keeping Bitcoin under cautious sentiment pressure.

MarketWhisper2h ago

Any prospects for U.S.-Iran talks? Bitcoin rebounds to 75K as MicroStrategy and ETF funds continue to pour in

The U.S.–Iran ceasefire agreement expires on Wednesday, and attention is focused on whether the two sides can resume negotiations. U.S. stocks fell amid heightened tensions, while bitcoin rebounded to $75K, driven mainly by institutional capital and ETF inflows, with MicroStrategy becoming the world’s largest bitcoin-holding institution.

ChainNewsAbmedia3h ago

Hungary's Fidesz Leader Orban Pledges to Unlock Frozen EU Funds Within Three Months

Peter Moaciur, head of Hungary's Fidesz party, announced plans to unblock EU funds by meeting key requirements within three months, focusing on anti-corruption, media freedom, and judicial independence to restore economic stability and investor confidence.

GateNews4h ago

BIS Warns Global Stablecoin Regulatory Fragmentation Will Fuel Arbitrage and Fragment Cross-Border Markets

The BIS's Pablo Hernandez de Cos warned that differing stablecoin regulations threaten cross-border markets and create arbitrage opportunities. He noted stablecoins' inadequacy for payments, potential market destabilization risks, and regulatory challenges linked to money laundering and sovereignty.

GateNews6h ago

Seven Israeli Officers Charged in Multimillion-Dollar Crypto Theft Ring

Israeli Security Forces Charged in Crypto Theft Case Israeli authorities have charged seven military and police officers with running a multimillion-dollar theft and bribery ring involving cryptocurrency, marking the second crypto-related criminal case to hit the country's defence establishment in

CryptoFrontier7h ago
Comment
0/400
No comments