← Back to News
CZ Sounds Alarm: GitHub Hack Exposes API Keys - P2P Traders, Rotate NOW!
P2P MarketsBearish2 min readMay 20, 2026BeInCrypto

CZ Sounds Alarm: GitHub Hack Exposes API Keys - P2P Traders, Rotate NOW!

A massive GitHub breach just put millions of API keys at risk. CZ is screaming for developers to rotate them NOW. This isn't just code; it's your trading accounts on the line.

3,800 REPOS GONE.

A hacker just snagged code from nearly 4,000 GitHub repos after a poisoned plugin infected an employee's machine. This isn't some abstract tech problem; it's a direct threat to the infrastructure that runs crypto trading.

This breach started with a single infected employee installing a malicious VS Code extension, proving even 'private' code isn't safe from internal compromise.

Roughly 3,800 repositories were compromised. The highest-risk credentials have already been rotated, but the damage is done, and the fallout is just beginning.

For Binance P2P and Bybit P2P merchants, this means your bots, your trading scripts, and any automated systems could be compromised. Exposed API keys can drain accounts in minutes. Assume everything is vulnerable and rotate your keys immediately.

If you're using any automated trading tools or have API keys embedded in your code, consider them compromised until proven otherwise. This is a wake-up call to secure your operations.

Share