Vercel security incident
Vercel security incident under third-party review!

Vercel reported unauthorized access to part of its internal systems following an incident involving the third-party service Context.ai, which was used by one of its employees. Through the compromise of his corporate Google Workspace account, attackers were able to gain limited access to internal infrastructure and environment variables that were not marked as critical.
Later, a message appeared on a hacker forum claiming the sale of allegedly obtained data, including access tokens (GitHub, NPM), fragments of source code, and a file containing employee data. The authenticity of these claims has not been officially confirmed.
The company stated that major open-source projects, including Next.js and Turbopack, were not affected, and that the development infrastructure continues to operate normally. A supply chain security review is also underway, along with strengthened security measures.
Some Web3 projects using Vercel for frontends temporarily rotated access keys as a precautionary measure, while no evidence of compromise of user funds or smart contracts has been identified.