Vercel Breached via Context.ai AI Platform
An attacker compromised a Vercel employee through Context.ai, escalated into Vercel's internal environments, and extracted customer environment variables. ShinyHunters listed the stolen data for $2 million; Vercel engaged Mandiant and law enforcement. The incident is now documented in three separate security bulletins, which is thorough.
Severity: Unrated · Category: Supply Chain
Impact: Internal systems compromised · Customer credentials exposed · Data listed for $2M
Source: Vercel Security Bulletin · BleepingComputer, Apr 2026
How Fencio prevents this
The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.
Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.