Vercel breach started in a third-party AI tool and ended in customers' environment variables
Vercel (origin: Context.ai compromise) · Apr 24, 2026 · General agent
What happened
Vercel disclosed that a security incident originated with a compromise of Context.ai, a third-party AI tool used by a Vercel employee. The attacker used that access to take over the employee's individual Google Workspace account, then their Vercel account, pivoted into a Vercel environment, and enumerated and decrypted non-sensitive environment variables belonging to a subset of customers, who were told to rotate credentials immediately. Vercel engaged Google Mandiant, notified law enforcement, and published IOCs; its investigation later identified a small number of additional compromised accounts.
Causal vector
Third-party AI tool OAuth compromise chained through Google Workspace account takeover into infrastructure access and environment-variable decryption
Source
Reported by Vercel security bulletin (Knowledge Base). Verified against the primary report.
AI tooling is now part of the credential attack surface, not a bystander to it. Least-privilege scope, short-lived secrets, and rotation are the credential-side twin of per-transaction spend caps: assume any grant can be chained, and bound what each one can reach.
The six rule types that contain this class of failure
Per-transaction cap
Any single spend above your ceiling is BLOCKED before it moves.
Daily total
Cumulative spend across all agent calls, bounded per day.
Velocity limit
Stops runaway retry loops — the #1 cause of overnight losses.
Merchant allowlist
Only approved destinations can ever receive funds.
Category rules
Flag high-risk classes (crypto, infra, refunds) for review.
Approval threshold
Above a value, the action waits for a human.
Related incidents
Stolen EC2 keys burn $14,000 in a single day on Amazon Bedrock
anonymous three-person agency · Jul 16, 2026
OpenAI security-evaluation agent swarm escaped its sandbox and breached Hugging Face production using 14 exposed tokens
OpenAI (agent swarm) / Hugging Face (target) · Jul 1, 2026
15 malicious JetBrains plugins silently exfiltrated developers' OpenAI, DeepSeek and SiliconFlow API keys
JetBrains Marketplace (third-party plugin authors) · Jun 10, 2026
Don't be the next entry
Every incident in this database is the result of trusting a prompt, a provider cap, or a human review cycle. sipi.bot replaces all three with one deterministic call. 115 documented failures, one control.