GitHub breach prompts API key warning for crypto devs

A GitHub breach exposed 3,800 internal repos. Changpeng Zhao urges crypto developers to rotate API keys. GitHub says customer data is safe and continues its investigation.

A major security breach at GitHub led to unauthorized access of around 3,800 internal repositories after a malicious VS Code extension compromised an employee's device. The hacking group TeamPCP claimed responsibility and is reportedly attempting to sell the stolen data for at least $50,000. GitHub assured that customer repositories, enterprise accounts, and organizational data were not affected. In response, the company removed the malicious extension, isolated the endpoint, and rotated critical credentials to contain the incident. This breach has heightened concerns in the crypto industry, as API keys stored in code—even in private repositories—could be at risk. Changpeng Zhao urged crypto developers to review and rotate any API keys in their codebases immediately. GitHub continues to investigate and monitor for suspicious activity, promising further updates as more information emerges.

Related News