Incident Overview
In April 2026, the Web3 frontend deployment platform Vercel (the primary maintainer of Next.js) was compromised by attackers. The attackers leveraged an AI tool, Context.ai, as an entry point. By exploiting the OAuth authorization mechanism, they obtained access permissions to Vercel accounts and subsequently exfiltrated environment variables from multiple Web3 projects deployed on the platform.
The leaked data included sensitive information such as API keys, RPC endpoints, and database connection strings. Notably, Vercel was preparing for its IPO at the time, and this security incident significantly impacted its reputation and investor confidence.
The attack can be divided into three stages:
- Infiltration Phase: Attackers exploited a vulnerability in Context.ai’s OAuth mechanism to gain high-privilege access to enterprise accounts.
- Exfiltration Phase: Sensitive environment variables were scanned and extracted, including both those labeled as “sensitive” and those that were not.
- Exploitation Phase: The stolen credentials were used to access backend systems, potentially leading to large-scale theft of user assets.
Technical Analysis
The core techniques used in this attack combine AI-assisted social engineering with OAuth permission abuse:
- OAuth Authorization Hijacking:
Attackers obtained legitimate OAuth authorization for Context.ai through methods such as phishing or vulnerability exploitation. Unlike traditional password-based attacks, once OAuth authorization is compromised, it grants attackers persistent access rather than a one-time login session. - Environment Variable Scanning and Extraction:
With the acquired permissions, attackers scanned and extracted environment variables from Web3 projects hosted on Vercel. These variables often contain high-value information such as API keys and database connection strings, effectively serving as “master keys” to backend systems. - Disruption of Frontend–Backend Trust Chain:
Instead of directly attacking smart contracts or on-chain protocols, attackers compromised the trust relationship between frontend infrastructure and backend systems, ultimately undermining the security of the entire ecosystem.
Security Recommendations
For Service Providers:
- Environment Variable Classification and Protection:
Implement strict classification policies for environment variables. Ensure high-privilege credentials (e.g., API keys) are labeled as “sensitive” and receive enhanced protection. - Principle of Least Privilege:
Grant third-party tools (such as AI services) only the minimum permissions necessary for operation. - Automated Credential Rotation:
Establish automated credential rotation mechanisms. For high-value projects, regularly rotate sensitive data such as API keys. - Third-Party Tool Auditing:
Conduct regular security audits of third-party tools with high-level access to enterprise accounts, and revoke unnecessary authorizations.
For Users:
- Multi-Channel Verification:
For any instruction involving financial transactions, perform secondary verification through official channels (e.g., official websites or verified social media accounts). - Beware of Unofficial Frontends:
Avoid using unverified third-party frontend interfaces, especially those requesting additional permissions. - Cautious Frontend Interaction:
Do not rely solely on frontend-displayed asset data. Always verify token balances and contract states directly through blockchain explorers.
Reference
“Vercel Breach: AI Tool Context.ai Becomes Attack Vector, Web3 Frontend Security Alert Raised; Solana DEX Orca First to Rotate Credentials”
http://www.120btc.com/zixun/qukuai/675497500.html
Insight Report Source: Global Cybersecurity Alliancehttps://www.gcsa.org
Get updates in your inbox
We respect your privacy. See our Privacy Policy