# @shawmakesmagic: Vercel breach exposed thousands of npm, PyPI tokens and keys Source: https://x.com/shawmakesmagic/status/2045952673107833332?s=12 This vercel thing is a fucking apocalypse Hundreds possibly thousands of npm, pypi etc tokens not to mention tents of thousands of email, cloud provider keys etc Like why was this not encrypted what the actual fuck ## Comments **mishaderidder.eth**: it was encrypted at rest https://news.kiwistand.com/stories/rauchg-Vercel-breach-via-compromised-Contextai-account-limited-impact?index=0x69e6a1fc86947d53959428df2157e355d7a50dbac9efc09ea0bc3a40c3236878aa5c58b2 **mishaderidder.eth**: Bottom line is the hack highlights a critical security gap: encryption at rest is only effective when properly configured. Even when encryption features are offered, user configuration errors or unclear defaults can leave sensitive data exposed.