• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Taiwanese AI startup Zeabur leaks environment variables! Numerous users’ Anthropic, OpenAI, and OpenRouter API keys stolen.

Taiwanese AI startup Zeabur leaks environment variables! Numerous users’ Anthropic, OpenAI, and OpenRouter API keys stolen.

KOCPC Editor by KOCPC Editor
August 29, 2026
in Anti-Virus Software and Internet Security, Latest Technology News

Taiwan startup cloud deployment platform Zeabur confirmed on August 27 that a security incident had occurred, in which a set of internal service credentials was accessed without authorization, leading to the exposure of some users’ environment variables stored in their projects. Zeabur founder Lin Yuanlin wrote on Threads.to express,已實際觀察到 Anthropic、OpenAI、OpenRouter 的 API 金鑰遭到盜用的情況。

Zeabur environment variables leaked! Anthropic, OpenAI, and OpenRouter API keys stolen.

Incident details: Internal credentials were stolen, leading to large-scale exposure of environment variables.

According to Zeabur Official statementThe attacker obtained a set of internal service credentials and used them to access the environment variable settings of some user projects. These environment variables contained a large number of sensitive credentials for third-party services, including API keys or tokens for platforms such as OpenAI, Anthropic, OpenRouter, Gemini, GitHub, AWS, Cloudflare, Stripe, as well as confidential information such as database connection strings, passwords, and JWT_Secret.

Zeabur would like to specifically remind users that even if they manually change the names of environment variables, as long as the values stored in them match the credential formats recognizable by AWS, GitHub, Anthropic, OpenRouter, OpenAI, or Stripe, the system will still confirm that these credentials have been exposed to attackers.

This incident highlights a common security risk on cloud deployment platforms. For convenience, developers often store API keys for third-party services directly on the platform, but once these keys leak, attackers can bypass the original developer’s authorization mechanisms and directly invoke paid API services. Using OpenAI’s API as an example, once attackers obtain the key, they can freely use GPT models, while the resulting charges are borne by the original account holder.

The founder publicly apologized and promised to take responsibility.

Zeabur founder Lin Yuanlin publicly apologized afterward, stating that the team had already completed initial containment on the day the anomaly was detected, and is currently continuing to monitor for any further abnormal activity. The team has notified all potentially affected users individually and is cooperating with upstream vendors and law enforcement agencies in the investigation.

 
在 Threads 查看

Regarding the actual scale of losses, which has drawn the most external concern, Zeabur said it still needs time to verify the scope of impact and individual losses. It will proceed with compensation and related follow-ups, and has promised to take responsibility for this incident.

The two batches of notifications use different standards; even those who did not receive a notification should check.

This time, Zeabur issued two batches of notifications in total, each with a different detection method. Zeabur therefore recommends that even users who did not receive official notifications should proactively check the credentials currently stored in their project environment variables to confirm whether any third-party service API keys have been exposed on the Zeabur platform.

Zeabur specifically emphasized that simply creating a new API key will not automatically invalidate the old key; users must separately perform a revoke procedure to truly cut off access for stolen credentials.

AI Hub service suspended; suspicious activity detected in LiteLLM.

During the investigation, Zeabur discovered suspicious activity in LiteLLM, which is used by AI Hub, and is currently still confirming whether it is related to this security incident. Zeabur has temporarily suspended the AI Hub service at the first opportunity to conduct a review. According to Zeabur’s status page records, this suspicious LiteLLM activity was reported on August 28 at 5:42 PM (UTC).

Impact on the developer community

Zeabur Zeabur is a cloud deployment platform that has risen to prominence in Taiwan in recent years, known for its one-click deployment service, especially popular among the Vibe Coding community. The platform supports deploying applications directly from GitHub and automatically manages infrastructure such as environment variables, databases, domains, and SSL. Thanks to its low barrier to entry, many individual developers and small teams rely on Zeabur to host a wide variety of applications, from Telegram bots to AI agent tools.

The severity of the environment variable leak incident lies in the fact that developers are accustomed to storing API keys for major AI services—including OpenAI, Anthropic, OpenRouter, and others—in environment variables. Once attackers obtain these keys, they can not only steal users’ API credits but also use them to access deeper third-party service data. For commercial services that rely on API keys to operate, the impact could be even more far-reaching.

Actions users should take immediately

Zeabur recommends that all users who have stored API keys on its platform take the following steps immediately: First, revoke all third-party service API keys that were ever stored in Zeabur projects and create new keys. Second, review recent API usage and billing to confirm whether there have been any abnormal calls. Third, if you use multiple services, such as OpenAI, Anthropic, AWS, etc., log in to each platform one by one to check whether your credentials are secure and whether there are any unknown keys. Additionally, it is also recommended to enable multi-factor authentication (MFA) and usage alert features on each platform so that you can be promptly informed when anomalies occur. If your API key is confirmed to have been misused, you can visit the official Zeabur-providedTechnical Support PageRegister, and the manufacturer will promptly proceed with verification and compensation.

The Zeabur incident once again reminds the entire developer community that while cloud deployment brings tremendous convenience, the security protection of centrally managed environment variables on platforms is of critical importance. For individual developers and small teams, distributing API keys across multiple locations, rotating them regularly, and enabling usage monitoring may be fundamental self-protection measures to reduce similar losses.

Source: KOCPC Chinese

Tags: CybersecurityZeabur

Recent Posts

  • Pikachu wreaks havoc at Apple Park! In his final week before stepping down, Tim Cook and John Ternus drum up hype for the Pokémon World Championships.
  • Taiwanese AI startup Zeabur leaks environment variables! Numerous users’ Anthropic, OpenAI, and OpenRouter API keys stolen.
  • Toei Games will make its first-ever appearance at Tokyo Game Show 2026, bringing 3 original titles including KILLA.
  • Rockstar’s Biggest Ever! 18 Key Takeaways from the GTA6 Extended Preview and Media Interviews
  • Think twice before buying an iMac: can you accept these 5 drawbacks?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology