Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
GitHub Internal Repositories Breached, Crypto Developers Warned to Rotate API Keys
00

GitHub Internal Repositories Breached, Crypto Developers Warned to Rotate API Keys

May 20, 2026

GitHub detected unauthorized access to internal repositories on May 19, 2026. TeamPCP claims to have stolen data from nearly 4,000 private repositories and is selling the dataset on dark web forums with asking prices exceeding $50,000. The Google Threat Intelligence Group identified TeamPCP as UNC6780, a financially motivated actor. Changpeng Zhao urged developers to rotate API keys on May 20, 2026.

GitHub internal repositories breach

  • ▪GitHub removed the malicious extension version and isolated the endpoint immediately after detecting the breach
  • ▪GitHub detected unauthorized access to GitHub's internal repositories on May 19, 2026
  • ▪GitHub stated that the unauthorized access involved exfiltration of roughly 3,800 repositories
  • ▪GitHub announced on May 20, 2026 that the activity only involved exfiltration of GitHub-internal repositories
  • ▪GitHub rotated important secrets overnight and within the same day of the breach, prioritizing the most sensitive credentials
  • ▪The GitHub breach resulted from a malicious Visual Studio Code extension placed on a compromised employee's device
  • ▪GitHub has not found evidence that user repositories, enterprise accounts, or other customer data stored outside internal systems were impacted by the breach

UNC6780 supply chain attack

  • ▪The Trivy Vulnerability Scanner exploitation by UNC6780 affected over 1,000 firms, including Cisco
  • ▪UNC6780's focus has consistently been on CI/CD setups and developer tools, where deeper system access can be obtained through privileged tokens and automation credentials
  • ▪The Google Threat Intelligence Group identified TeamPCP as UNC6780, a financially motivated actor with a track record of supply chain breaches
  • ▪UNC6780 was linked to campaigns targeting LiteLLM and Checkmarx, focusing on credential harvesting in software delivery pipelines
  • ▪UNC6780 was connected to the Trivy Vulnerability Scanner exploitation through CVE-2026-33634 in early 2026

TeamPCP dark web data sale

  • ▪TeamPCP claims that almost 4,000 private repositories connected to GitHub's core infrastructure are among the stolen content
  • ▪TeamPCP distributed a file index and screenshots displaying repository archive names to support their claim of the GitHub breach
  • ▪TeamPCP's reported asking prices for the stolen GitHub dataset exceed $50,000
  • ▪TeamPCP claims to have stolen source code and proprietary organizational data from GitHub and is selling the dataset on dark web cybercrime forums

Crypto developer API key warnings

  • ▪Changpeng Zhao asked developers to examine and rotate any API keys in code immediately after GitHub revealed the breach on May 20, 2026
  • ▪Multiple trading, custody, and data services that rely on crypto API connections may be affected by a single supply chain incursion when code repositories contain or process API keys, automation tokens, and CI/CD credentials

Crypto API ecosystem vulnerabilities

  • ▪The crypto API ecosystem largely relies on developer tooling and third-party integrations
  • ▪The GitHub hack highlights how vulnerable contemporary crypto infrastructure can become when core development environments are compromised

Perspective of Crypto developers and exchanges

  • ▪Multiple trading, custody, and data services that rely on crypto API connections may be affected by a single supply chain incursion when code repositories contain or process API keys, automation tokens, and CI/CD credentials
  • ▪Changpeng Zhao asked developers to examine and rotate any API keys in code immediately after GitHub revealed the breach on May 20, 2026

3 sources

Beincrypto
Changpeng Zhao Warns Crypto Devs to Rotate API Keys After GitHub Hack
View source article
Coinpedia
GitHub Is Hacked
View source article
Cryptopolitan
Binance founder warns developers to rotate API keys after GitHub internal repository exposure
View source article

Featured stories

View more in Crypto

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources

OpenAI and Anthropic CEOs called to appear at Australian AI inquiry

Sep 27, 2026 · 2 sources

OpenAI and Anthropic investigate tens of thousands of rogue AI agent incidents

Sep 26, 2026 · 2 sources

Story comments

Loading comments…

Related entities

Blockchain Security

People Involved

Changpeng Zhao

Related Projects

Binance

Topics

CryptoAI securitySoftware supply chain security

Featured stories

View more in Crypto

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources

OpenAI and Anthropic CEOs called to appear at Australian AI inquiry

Sep 27, 2026 · 2 sources

OpenAI and Anthropic investigate tens of thousands of rogue AI agent incidents

Sep 26, 2026 · 2 sources