< Back to all clusters
[TECHNOLOGY] · Taiwan · 2 sources

started · updated

Zeabur cloud platform suffers security breach leaking AI API keys

Cloud deployment platform Zeabur has experienced a security breach involving the leak of user environment variables. The attack targeted AI service API keys, including those for OpenAI, Anthropic, and OpenRouter, potentially leading to unauthorized usage charges for affected users.

According to Zeabur founder Lin Yuanlin, attackers gained access to the main database by exploiting a leaked AWS management key to enter a legacy "shared cluster" that was in the process of being decommissioned. From there, they obtained VPN access to the system control plane. While the core backend services remain isolated, the breach allowed for targeted queries of user environment variables.

Zeabur has stated that credit card information remains secure as payment data is handled by Stripe and is inaccessible to the company's internal staff. Regarding claims on the dark web of a complete data leak, the company noted that current evidence does not support the authenticity of such claims.

As of the latest updates, Zeabur has completed key rotations and enhanced system monitoring. The company has initiated a compensation process for users who can provide proof of unauthorized charges, with a goal to complete arrangements by September 30. Approximately 63% of verified claims have already been processed.

Entities

AWS · Lin Yuanlin · OpenAI · Stripe · Zeabur