Back to overview
Degraded

Unauthorized Access to Project Environment Variable Data

Aug 28, 2026 at 7:11am UTC
Affected services
Dashboard (zeabur.com/projects)

Updated
Aug 28, 2026 at 5:42pm UTC

During our ongoing investigation, we identified suspicious activity involving LiteLLM, which is used by the Zeabur AI Hub service. We are currently investigating whether this activity is related to the incident.

As a precautionary measure and to prevent any potential further impact, we are temporarily suspending Zeabur AI Hub services while the investigation continues.

Created
Aug 28, 2026 at 7:11am UTC

We detected unauthorized access to an internal service credential that was used to retrieve project environment variable records. We revoked the affected credential, blocked the access path, and contained the incident on the same day.

Our investigation confirmed exposure of environment variables with the following key names:

ACCESS_TOKEN, API_SECRET, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, CF_API_TOKEN, CLIENT_SECRET, CLOUDFLARE_API_TOKEN, DIGITALOCEAN_TOKEN, GEMINI_API_KEY, GITHUB_PAT, GITHUB_TOKEN, GOOGLE_API_KEY, LINODE_TOKEN, PRIVATE_KEY, STRIPE_PUBLISHABLE_KEY, STRIPE_SECRET_KEY, ANTHROPIC_API_KEY, OPENROUTER_API_KEY, OPENAI_API_KEY, DATABASE_URL, JWT_SECRET, MONGODB_URI, MYSQL_PASSWORD, POSTGRES_PASSWORD, REDIS_PASSWORD, and SECRET_KEY.

We also confirmed exposure of credentials stored under custom variable names when their values matched identifiable AWS, GitHub, Anthropic, OpenRouter, OpenAI, or Stripe credential formats.

Affected users are being notified directly with the relevant projects, services, environments, and recommended rotation actions. We strongly recommend that notified users immediately revoke and replace all listed credentials and review the corresponding databases and third-party services for unusual access, usage, or charges.

At this time, we have found no evidence that Zeabur account credentials, personal information, server data, payment information, or credit card information were accessed. Our investigation remains ongoing, and we will provide further updates as they become available.