<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/next-js-developer-vercel-warns-customer-creds-compromised-rja0031aa" -->

---
title: Next.js developer Vercel warns customer creds compromised
description: Vercel disclosed a security incident in which an attacker compromised a third-party AI tool (Context.ai) used by a Vercel employee, then leveraged stolen OAuth...
canonical: https://daily.dev/posts/next-js-developer-vercel-warns-customer-creds-compromised-rja0031aa
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Next.js developer Vercel warns customer creds compromised | daily.dev
og:description: Vercel disclosed a security incident in which an attacker compromised a third-party AI tool (Context.ai) used by a Vercel employee, then leveraged stolen OAuth...
og:url: https://daily.dev/posts/next-js-developer-vercel-warns-customer-creds-compromised-rja0031aa
og:image: https://api.daily.dev/og/posts/rJA0031AA.png
og:image:alt: Next.js developer Vercel warns customer creds compromised
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Next.js developer Vercel warns customer creds compromised

**[The Register](https://daily.dev/sources/theregister)** · 3 min read · 0 upvotes · 0 comments

## Summary

Vercel disclosed a security incident in which an attacker compromised a third-party AI tool (Context.ai) used by a Vercel employee, then leveraged stolen OAuth tokens to access Vercel's Google Workspace and internal environments. This exposed environment variables and credentials for a limited subset of customers. Context.ai had suffered an AWS breach in March, which CrowdStrike investigated but apparently missed the OAuth token compromise. The incident highlights risks of agentic AI tools with broad OAuth permissions connecting to enterprise accounts.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://go.theregister.com/feed/www.theregister.com/2026/04/20/vercel_context_ai_security_incident/>

## Similar posts on daily.dev

- [Vercel Data Breach Linked to Earlier Context.ai Compromise](https://daily.dev/posts/vercel-data-breach-linked-to-earlier-context-ai-compromise-jzp24ggnp) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#nextjs](https://daily.dev/tags/nextjs), [#ai-agents](https://daily.dev/tags/ai-agents), [#vercel](https://daily.dev/tags/vercel), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/next-js-developer-vercel-warns-customer-creds-compromised-rja0031aa)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Next.js developer Vercel warns customer creds compromised","url":"https://daily.dev/posts/next-js-developer-vercel-warns-customer-creds-compromised-rja0031aa","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/next-js-developer-vercel-warns-customer-creds-compromised-rja0031aa"},"datePublished":"2026-04-20T07:37:43.172Z","dateModified":"2026-04-20T07:38:34.007Z","description":"Vercel disclosed a security incident in which an attacker compromised a third-party AI tool (Context.ai) used by a Vercel employee, then leveraged stolen OAuth...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ef50e376682ad1795910268b00b81965?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ef50e376682ad1795910268b00b81965?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Register","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Register","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/66aa2113fdad463992ffcbf0e8963fda","url":"https://daily.dev/sources/theregister"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/next-js-developer-vercel-warns-customer-creds-compromised-rja0031aa","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,nextjs,ai-agents,vercel,oauth","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Register","item":"https://daily.dev/sources/theregister"},{"@type":"ListItem","position":3,"name":"Next.js developer Vercel warns customer creds compromised"}]}
```

