Binance founder warns developers to rotate API keys after GitHub internal repository exposure

Source Cryptopolitan

Changpeng Zhao has asked developers to examine and rotate any API keys in code immediately after GitHub revealed on May 20 that hackers had gained unauthorized access to its internal repositories. The incident resulted from a malicious Visual Studio Code extension placed on a compromised employee’s device.

GitHub detected unauthorized access to GitHub’s internal repositories on May 19. In response, the platform immediately removed the malicious extension version and isolated the endpoint.

The Microsoft-owned platform stated that it is investigating unauthorized access to internal repositories and has not yet found any evidence that user repositories, enterprise accounts, or other customer data stored outside those internal systems were impacted.

The code hosting platform also stated that while the inquiry is still ongoing, it is keeping a careful eye on the situation. 

GitHub went on X to announce that the activity only involved exfiltration of GitHub-internal repositories after the assessment. It added that its findings were consistent with the attacker’s claims of accessing roughly 3,800 repositories.

The code hosting platform stated that it reduced the risk by rotating important secrets overnight and within the same day, prioritizing the most sensitive credentials.

It added that more steps will be taken as the investigation progresses and that it is still analyzing logs, confirming the efficacy of the secret rotation procedure, and monitoring for any possible follow-on activity. The platform also stated that after the investigation is finished, a more comprehensive report would be released.

GitHub breach attributed to UNC6780 supply chain attack

The breach of GitHub’s internal systems has been attributed to a threat actor using the pseudonym TeamPCP. The group claims to have stolen source code and proprietary organizational data, and is now selling the dataset on dark web cybercrime forums. The reported asking prices exceed $50,000.
According to the attackers, almost 4,000 private repositories connected to GitHub’s core infrastructure are among the stolen content. They have allegedly distributed a file index and screenshots displaying many repository archive names to support the assertion. They also claim that samples can be given to serious purchasers as evidence of genuineness.
The Google Threat Intelligence Group has identified TeamPCP as UNC6780, a financially motivated actor with a track record of supply chain breaches. The Intelligence Group noted that TeamPCP’s purported focus has consistently been on CI/CD setups and developer tools, where deeper system access can be obtained through privileged tokens and automation credentials. 

The group was connected to the Trivy Vulnerability Scanner exploitation through CVE-2026-33634 in early 2026. The exploitation affected over 1,000 firms, including Cisco. They were also linked to campaigns targeting LiteLLM and Checkmarx, focusing on credential harvesting in software delivery pipelines. 

Crypto APIs face rising supply chain exposure

Following the GitHub hack and Changpeng Zhao’s warning, the crypto API ecosystem, which largely relies on developer tooling and third-party integrations, has come under closer scrutiny. 

The GitHub hack highlights how vulnerable contemporary crypto infrastructure can become when core development environments are compromised, especially when code repositories contain or process API keys, automation tokens, and CI/CD credentials. Multiple trading, custody, and data services that rely on these connections may be affected by a single supply chain incursion in such configurations.

Cryptopolitan reported on March 26, 2026, that a correct API is crucial for any cryptocurrency project, whether you’re developing a trading bot, a DeFi analytics dashboard, or a portfolio tracker. The report also noted that delivering thorough, accurate, and low-latency information promotes rather than impedes development. 

API infrastructure providers that facilitate trading, analytics, and blockchain connectivity are attracting increasing industry attention. Cryptopolitan reported that platforms such as CoinStats API, CoinGecko API, CoinMarketCap API, CCData (CryptoCompare), CoinAPI, Kaiko, Glassnode, Covalent, Alchemy, Infura, QuickNode, and Bitquery demonstrate how exchanges, fintech apps, and blockchain services rely on standardized APIs to support growth and enable real-time data flows. 

The smartest crypto minds already read our newsletter. Want in? Join them.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Solana’s White Whale: Rug Pull, Trap, or the Perfect Meme Coin?Owing to the volatility often seen in the Solana meme coin market, survival itself is rare. Yet The White Whale (WHITEWHALE), a token born on Pump.fun launchpad in late 2025, has defied the odds.WHITE
Author  Beincrypto
Feb 04, Wed
Owing to the volatility often seen in the Solana meme coin market, survival itself is rare. Yet The White Whale (WHITEWHALE), a token born on Pump.fun launchpad in late 2025, has defied the odds.WHITE
placeholder
Goldman Sachs Reveals $2.3 Billion Crypto Investment, Including Bitcoin and XRPGoldman Sachs disclosed significant crypto exposure in its Q4 2025 13F filing, revealing more than $2.36 billion in digital asset holdings. The filing shows $1.1 billion in Bitcoin, $1.0 billion in Et
Author  Beincrypto
Feb 11, Wed
Goldman Sachs disclosed significant crypto exposure in its Q4 2025 13F filing, revealing more than $2.36 billion in digital asset holdings. The filing shows $1.1 billion in Bitcoin, $1.0 billion in Et
placeholder
3 Space Stocks To Watch Amid Elon Musk’s SpaceX IPO HypeA $1.75 trillion IPO is about to redefine which space stocks to watch this summer. SpaceX is closing in on the largest IPO ever. The public S-1 is due late May, with the listing slated for late June o
Author  Beincrypto
May 09, Sat
A $1.75 trillion IPO is about to redefine which space stocks to watch this summer. SpaceX is closing in on the largest IPO ever. The public S-1 is due late May, with the listing slated for late June o
placeholder
Smart Money is Leaving XRP: Will Ripple’s Altcoin Dump?XRP price sits less than 1% above the floor of a three-month rising channel, after smart money’s quiet exit on May 17 triggered a chain of bearish technical signals.The last time smart money bailed th
Author  Beincrypto
9 hours ago
XRP price sits less than 1% above the floor of a three-month rising channel, after smart money’s quiet exit on May 17 triggered a chain of bearish technical signals.The last time smart money bailed th
placeholder
Goldman Sachs takes lead on SpaceX IPO as prospectus expected WednesdayGoldman Sachs will take the lead left seat for SpaceX’s initial public offering, positioning the firm as the most prominent player in what could become the biggest IPO of all time, according to CNBC Morgan Stanley comes next. BofA, Citi, and JPMorgan complete the rest of the senior positions. This brings the SpaceX IPO out...
Author  Cryptopolitan
9 hours ago
Goldman Sachs will take the lead left seat for SpaceX’s initial public offering, positioning the firm as the most prominent player in what could become the biggest IPO of all time, according to CNBC Morgan Stanley comes next. BofA, Citi, and JPMorgan complete the rest of the senior positions. This brings the SpaceX IPO out...
goTop
quote