• bitcoinBitcoin (BTC) $ 77,603.00
  • ethereumEthereum (ETH) $ 2,321.42
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 1.44
  • bnbBNB (BNB) $ 637.88
  • usd-coinUSDC (USDC) $ 0.999816
  • solanaSolana (SOL) $ 86.30
  • tronTRON (TRX) $ 0.324440
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.098243
  • whitebitWhiteBIT Coin (WBT) $ 54.92
  • usdsUSDS (USDS) $ 0.999757
  • hyperliquidHyperliquid (HYPE) $ 41.21
  • leo-tokenLEO Token (LEO) $ 10.24
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.251273
  • bitcoin-cashBitcoin Cash (BCH) $ 457.12
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 9.40
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 369.78
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • zcashZcash (ZEC) $ 360.07
  • canton-networkCanton (CC) $ 0.152362
  • stellarStellar (XLM) $ 0.173508
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • memecoreMemeCore (M) $ 4.26
  • daiDai (DAI) $ 0.999578
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 56.64
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • avalanche-2Avalanche (AVAX) $ 9.43
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • hedera-hashgraphHedera (HBAR) $ 0.091107
  • ethena-usdeEthena USDe (USDE) $ 0.999318
  • suiSui (SUI) $ 0.949442
  • wethWETH (WETH) $ 2,268.37
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007568
  • paypal-usdPayPal USD (PYUSD) $ 0.999671
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.33
  • crypto-com-chainCronos (CRO) $ 0.069383
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,705.92
  • bittensorBittensor (TAO) $ 250.43
  • global-dollarGlobal Dollar (USDG) $ 0.999754
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.074936
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • pax-goldPAX Gold (PAXG) $ 4,708.41
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • mantleMantle (MNT) $ 0.648957
  • polkadotPolkadot (DOT) $ 1.26
  • uniswapUniswap (UNI) $ 3.26
  • skySky (SKY) $ 0.083374
  • nearNEAR Protocol (NEAR) $ 1.41
  • falcon-financeFalcon USD (USDF) $ 0.997167
  • okbOKB (OKB) $ 83.87
  • pi-networkPi Network (PI) $ 0.170288
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • aster-2Aster (ASTER) $ 0.669086
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • ripple-usdRipple USD (RLUSD) $ 0.999902
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • aaveAave (AAVE) $ 95.19
  • usddUSDD (USDD) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 1.98
  • internet-computerInternet Computer (ICP) $ 2.47
  • ethereum-classicEthereum Classic (ETC) $ 8.56
  • bfusdBFUSD (BFUSD) $ 0.999799
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • ondo-financeOndo (ONDO) $ 0.264923
  • kucoin-sharesKuCoin (KCS) $ 8.47
  • gatechain-tokenGate (GT) $ 7.38
  • morphoMorpho (MORPHO) $ 1.87
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • pump-funPump.fun (PUMP) $ 0.001786
  • quant-networkQuant (QNT) $ 71.74
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • united-stablesUnited Stables (U) $ 0.999997
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.06
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • cosmosCosmos Hub (ATOM) $ 1.99
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.093548
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • algorandAlgorand (ALGO) $ 0.107518
  • ethenaEthena (ENA) $ 0.108238
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • render-tokenRender (RENDER) $ 1.81
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • kaspaKaspa (KAS) $ 0.033915
  • nexoNEXO (NEXO) $ 0.903264
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • worldcoin-wldWorldcoin (WLD) $ 0.261311
  • arbitrumArbitrum (ARB) $ 0.128875
  • wbnbWrapped BNB (WBNB) $ 759.61
  • stable-2​​Stable (STABLE) $ 0.035582
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.963910
  • blockchain-capitalBlockchain Capital (BCAP) $ 82.76
  • filecoinFilecoin (FIL) $ 0.942743
  • official-trumpOfficial Trump (TRUMP) $ 2.99
  • justJUST (JST) $ 0.080781
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.007897
  • hash-2Provenance Blockchain (HASH) $ 0.011124
  • dexeDeXe (DEXE) $ 13.45
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • vechainVeChain (VET) $ 0.007309
  • midnight-3Midnight (NIGHT) $ 0.037349
  • beldexBeldex (BDX) $ 0.080170
  • jupiter-exchange-solanaJupiter (JUP) $ 0.174277
  • xdce-crowd-saleXDC Network (XDC) $ 0.030706
  • ousgOUSG (OUSG) $ 115.02
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usdtbUSDtb (USDTB) $ 0.999821
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • ghoGHO (GHO) $ 0.999016
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • bonkBonk (BONK) $ 0.000006
  • usual-usdUsual USD (USD0) $ 0.998027
  • yldsYLDS (YLDS) $ 0.999820
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008535
  • edgexedgeX (EDGE) $ 1.46
  • true-usdTrueUSD (TUSD) $ 1.00
  • chilizChiliz (CHZ) $ 0.047920
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.51
  • a7a5A7A5 (A7A5) $ 0.012490
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • siren-2Siren (SIREN) $ 0.665994
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.209046
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • dashDash (DASH) $ 36.64
  • tbtctBTC (TBTC) $ 70,942.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.706854
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • euro-coinEURC (EURC) $ 1.17
  • adi-tokenADI (ADI) $ 4.12
  • blockstackStacks (STX) $ 0.227990
  • sei-networkSei (SEI) $ 0.061756
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999052
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • tezosTezos (XTZ) $ 0.372544
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • layerzeroLayerZero (ZRO) $ 1.59
  • venice-tokenVenice Token (VVV) $ 8.66
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • aerodrome-financeAerodrome Finance (AERO) $ 0.426796
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • usxUSX (USX) $ 0.999665
  • cocaCOCA (COCA) $ 1.30
  • ether-fiEther.fi (ETHFI) $ 0.450672
  • kinesis-goldKinesis Gold (KAU) $ 152.32
  • monadMonad (MON) $ 0.030580
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • sun-tokenSun Token (SUN) $ 0.018750
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • spx6900SPX6900 (SPX) $ 0.383528
  • decredDecred (DCR) $ 20.10
  • zebec-networkZebec Network (ZBCN) $ 0.003536
  • injective-protocolInjective (INJ) $ 3.43
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.342120
  • curve-dao-tokenCurve DAO (CRV) $ 0.225418
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • hastra-primePRIME (PRIME) $ 1.03
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • celestiaCelestia (TIA) $ 0.360563
  • lido-daoLido DAO (LDO) $ 0.381007
  • gnosisGnosis (GNO) $ 122.36
  • conflux-tokenConflux (CFX) $ 0.061793
  • flokiFLOKI (FLOKI) $ 0.000033
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • bitcoin-svBitcoin SV (BSV) $ 15.89
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • apenftAINFT (NFT) $ 0.00000032
  • crvusdcrvUSD (CRVUSD) $ 0.999633
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • pyth-networkPyth Network (PYTH) $ 0.051396
  • olympusOlympus (OHM) $ 18.89
  • doublezeroDoubleZero (2Z) $ 0.084198
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • kinesis-silverKinesis Silver (KAG) $ 76.30
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000052
  • jasmycoinJasmyCoin (JASMY) $ 0.005759
  • kaiaKaia (KAIA) $ 0.048318
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • usdaiUSDai (USDAI) $ 1.00
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

More users enter impact radius of Vercel exploit

0 0


The April 2026 Vercel security incident continues to extend past initial claims. The incident, which was said to involve what Vercel referred to as a “limited subset of customers,” has now expanded toward a much broader developer community, especially those building AI agent workflows.

In its recent security bulletin on April 19, which has been updated over time following its ongoing investigation, Vercel claims that developers who rely on packs of third-party API keys, LLM provider credentials, and tool calls are more open to such attacks.

How did the breach happen?

Unlike user speculations, Vercel was not the initial point of entry; it was compromised when a Context.ai employee with sensitive access privileges was breached via a Lumma Stealer malware infection.

The breach occurred when the employee downloaded a Roblox Auto-farm script and game exploit tools, which are major ways the malware is spread. This breach led to stolen user data, including Google Workspace login details and other access keys to platforms like Supabase, Datadog, and Authkit.

The attacker then made use of a stolen OAuth token to gain access to Vercel’s Google Workspace account. While Vercel is not a Context.ai user, an employee of theirs had an account with the platform, which was created using a Vercel enterprise account, and worst of all, had approved “allow all” permissions.

To make things worse, Vercel had enabled these broad permissions within its Google Workspace environment, granting easier access.

Once in, the attacker went on to decrypt non-sensitive environment variables stored in the system. However, they were unable to get access to sensitive data, as Vercel has those environment variables stored in a manner that prevents them from being accessed.

What does this mean for AI agent developers?

For developers, the concern lies more in the impact radius than in what was recorded as stolen. Most developers are worried that their workflows, which are wired together with credentials in plain environment variables, might be exposed to this breach. This is because most developers on Vercel commonly store important access keys in their deployment environments.

Furthermore, AI-powered projects could contain an OpenAI or Anthropic API key, a vector database connection string, a webhook secret, and a third-party tool token at the same time, which are not flagged by the system as sensitive because they require the developer to do so manually.

To battle this incident, Vercel has updated its product so that all newly created environment variables are marked sensitive by default and can only be made insensitive by the developer. While the development is a right step, it doesn’t make up for the variables that were stolen before the change occurred.

How far does the attack go?

According to Vercel, the attack may affect hundreds of users across several organizations, not just its own systems, but across the entire tech industry. This is because the OAuth app used in the attack was not limited to Vercel alone.

To reduce the attack’s effects, Vercel’s security team has shared the unique identifier of the compromised OAuth app, urging Google Workspace administrators and Google account holders to check whether it had access to their systems.

Additionally, Context.ai, with the help of Nudge Security CTO Jaime Blasco, also detected another OAuth permission grant, containing Google Drive access. To prevent further impact, Context.ai immediately alerted all affected customers and provided the necessary steps needed to prevent further breaches.



Source link

Leave A Reply

Your email address will not be published.