Connect with us
DAPA Banner

Crypto World

Hack at Vercel sends crypto developers scrambling to lock down API keys

Published

on

How a fake crypto app bypassed Apple's security

A breach at web infrastructure provider Vercel is forcing crypto teams to rotate API keys and do a deep inspection of their underlying code.

In a bulletin, Vercel said the hacker was able to grab behind-the-scenes settings that weren’t locked down, potentially exposing API keys — the digital credentials apps use to connect to other services. Those credentials act like digital passwords, allowing software to connect to databases, crypto wallets, and external services. In the wrong hands, they can be used to impersonate an app, burn through usage limits, or manipulate how it runs.

A post on cybercrime forum BreachForums claimed to be selling Vercel data for $2 million, including access keys and source code, though those claims have not been independently verified. Vercel said it has engaged incident response firms and law enforcement and is continuing to investigate whether any data was exfiltrated.

The company traced the intrusion to Context.ai, a third-party AI tool used by an employee, its CEO said in an X post, where a compromised Google Workspace connection allowed attackers to escalate access into Vercel’s internal environments. Vercel said environment variables marked as “sensitive” are stored in a way that prevents them from being read, and that there is no evidence that they were accessed.

Advertisement

The incident is drawing scrutiny because Vercel underpins frontend infrastructure for many crypto applications and is the primary steward of Next.js, one of the most widely used web development frameworks. Many Web3 teams host wallet interfaces and decentralized app dashboards on Vercel, relying on environment variables to store credentials that connect their frontends to blockchain data providers and backend services.

Solana-based decentralized exchange Orca said its frontend is hosted on Vercel and that it has rotated all deployment credentials as a precaution. The project added that its on-chain protocol and user funds were not affected.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

The $13 billion DeFi wipeout in two days, and it started with KelpDAO attack

Published

on

The $13 billion DeFi wipeout in two days, and it started with KelpDAO attack

The decentralized finance (DeFi) ecosystem is experiencing a sharp capital outflow following the weekend exploit of the KelpDAO protocol.

Leading DeFi lending platform Aave has lost $8.45 billion in deposits over the past 48 hours, driving a broader $13.21 billion decline in total value locked (TVL) across DeFi. TVL refers to the combined dollar value of crypto assets deposited across DeFi protocols, such as Aave, and is widely used as to measure liquidity and overall market activity.

Total value locked across DeFi fell from $99.497 billion to $86.286 billion, while Aave’s TVL declined by $8.45 billion to $17.947 billion over the same period, according to DefiLlama. Protocol-level data shows double-digit percentage drops across platforms, including Euler, Sentora, and Aave, with losses concentrated in lending, restaking, and yield strategies tied to the affected collateral.

The move stems from a $292 million exploit of Kelp’s bridge that allowed attackers to use stolen rsETH, a liquid re-staking token widely used in DeFi, as collateral to borrow funds on lending platforms.

Advertisement

Because these stolen tokens lacked legitimate collateral backing, borrowing against them created potential shortfalls for lenders. It’s similar to conning a traditional bank by depositing fake fiat and taking out loans against it, ultimately leaving the lender with bad debt.

Protocols responded by freezing affected markets, while panicked users withdrew funds, leading to a broad decline in total value locked.

Token prices have moved less sharply than deposits. The AAVE token is down about 2.5% over 24 hours, while UNI and LINK are down less than 1% over the same period, according to CoinDesk market data.

Peter Chung, head of research at Presto Research, said in a note the incident highlights risks in cross-chain infrastructure, particularly in verification systems used by bridges.

Advertisement

Early analysis suggests the issue may have originated in the verification layer rather than in smart contracts themselves.

Chung added that the episode also shows how interconnected DeFi protocols can transmit shocks beyond the initial point of failure, with withdrawal activity and market freezes extending to platforms without direct exposure to the exploit.

Source link

Advertisement
Continue Reading

Crypto World

Bitcoin Drops to $74K as US-Iran Tensions Flare

Published

on

Bitcoin Drops to $74K as US-Iran Tensions Flare

Bitcoin erased its weekend gains as it fell below $74,000 on Sunday after the US military seized an Iranian cargo ship, putting pressure on a ceasefire between the two countries. 

Bitcoin (BTC) had soared above $78,300 late Friday on Coinbase, its highest price since early February, but dropped to between $75,000 and $76,000 over the weekend after Iran said it would close vital oil routes in the Strait of Hormuz.

The cryptocurrency then sank sharply late on Sunday to briefly trade below $74,000 after the US military said it opened fire on, and later seized, an Iranian cargo ship it claimed tried to run its blockade of Iranian ports, with Tehran accusing the US of violating an agreed ceasefire. 

The two-week ceasefire between the US and Iran, which had helped boost the markets and temper oil prices, is set to end on Wednesday.

Advertisement
Bitcoin’s price in US dollars on Coinbase over the last five days has fallen over the weekend amid rising tensions between the US and Iran. Source: TradingView

Tehran has vowed to retaliate over the US military’s seizure of the ship and has rejected a new round of peace talks slated for Monday in Islamabad, Pakistan, due to the US blockade, Iranian state media reported.

Related: Bitcoin eyes $90K as whales absorb 20x daily BTC supply in 30 days

US stock futures sank Sunday night amid rising tensions, with S&P 500 futures dropping 0.8%, Nasdaq-100 futures falling 0.6% and Dow Jones futures declining 0.9%, or about 450 points.

Oil futures also soared amid the hostilities and Iran’s threat to close the Strait of Hormuz, with crude oil futures rising over 4.5% to over $95 a barrel.

The Crypto Fear & Greed index rose by two points to a score of 29 out of 100 on Monday, its highest score since late January, but which still indicated a sentiment of “fear.”

Advertisement

Magazine: Bitcoin will not hit $1M by 2030, says veteran trader Peter Brandt