Upstream Zeabur Platform Incident
Incident Summary
On August 27, 2026, Zeabur, the upstream deployment platform we use, detected unauthorized use of an internal service credential. The attacker used the credential to query project environment variables (Variables), which may have included API keys, access tokens, and other service credentials stored there.
For the full official announcement and remediation guidance, please refer to the Zeabur incident status page: https://status.zeabur.com/incident/1037896
Official Investigation Report
- Chinese: https://zeabur.com/zh-TW/blogs/august-2026-security-incident
- English: https://zeabur.com/blogs/august-2026-security-incident
sk5s Impact Assessment
We did receive an affected-user notification from Zeabur, which strongly suggests the environment variables of the affected project were retrieved. Key points for sk5s:
- The exposed environment variables included patterns matching high-risk credentials (API keys, tokens); older values should be considered retrieved
Actions Already Taken
In response to the environment-variable exposure, we have completed the following:
- Rotated all API keys, tokens, and access credentials for cloud and third-party services
- Rotated database connection passwords and application signing secrets
- Audited and cleaned up project environment variables, removing any data matching known exfiltration patterns
SSH and Other Credential Exposure — Conclusion
As of this update, based on Zeabur’s subsequent announcements and our own cross-checks and forensic review:
- No evidence has been found that VPS SSH keys (public/private) or other host login credentials were exposed in this incident
- Although no exposure has been found so far, as a precaution we still recommend users watch for any unusual sign-in activity on their accounts
Final Conclusion
Zeabur has now publicly disclosed the attack chain and forensic findings for this incident. The investigation and response phase is considered closed:
- The disclosed attack chain and scope of impact are largely consistent with our earlier assessment
- Our previously executed credential rotations, environment-variable cleanup, and strengthened monitoring remain in place
- If Zeabur later releases material updates or new risks are identified, we will post a separate notice to this channel. Otherwise, no further routine updates will be issued for this incident
Impact on Users
By design, sk5s applications currently do not store sensitive user data, so this incident poses no concrete data-exposure risk to end users:
- No game progress
- No payment or subscription features are offered, and no related records exist
Ongoing Monitoring
The strengthened monitoring and alerting on the related infrastructure will remain in place. If Zeabur later releases material updates or new risks are identified, we will post a notice to this channel as soon as we can.