expand_more
Homechevron_rightsk5s Security Noticeschevron_rightUpstream Zeabur Platform Incident
en•Aug 31, 2026
phone_iphoneandroid

Upstream Zeabur Platform Incident

Incident Summary

On August 27, 2026, Zeabur, the upstream deployment platform we use, detected unauthorized use of an internal service credential. The attacker used the credential to query project environment variables (Variables), which may have included API keys, access tokens, and other service credentials stored there.

For the full official announcement and remediation guidance, please refer to the Zeabur incident status page: https://status.zeabur.com/incident/1037896

Official Investigation Report

sk5s Impact Assessment

We did receive an affected-user notification from Zeabur, which strongly suggests the environment variables of the affected project were retrieved. Key points for sk5s:

  • The exposed environment variables included patterns matching high-risk credentials (API keys, tokens); older values should be considered retrieved

Actions Already Taken

In response to the environment-variable exposure, we have completed the following:

  • Rotated all API keys, tokens, and access credentials for cloud and third-party services
  • Rotated database connection passwords and application signing secrets
  • Audited and cleaned up project environment variables, removing any data matching known exfiltration patterns

SSH and Other Credential Exposure — Conclusion

As of this update, based on Zeabur’s subsequent announcements and our own cross-checks and forensic review:

  • No evidence has been found that VPS SSH keys (public/private) or other host login credentials were exposed in this incident
  • Although no exposure has been found so far, as a precaution we still recommend users watch for any unusual sign-in activity on their accounts

Final Conclusion

Zeabur has now publicly disclosed the attack chain and forensic findings for this incident. The investigation and response phase is considered closed:

  • The disclosed attack chain and scope of impact are largely consistent with our earlier assessment
  • Our previously executed credential rotations, environment-variable cleanup, and strengthened monitoring remain in place
  • If Zeabur later releases material updates or new risks are identified, we will post a separate notice to this channel. Otherwise, no further routine updates will be issued for this incident

Impact on Users

By design, sk5s applications currently do not store sensitive user data, so this incident poses no concrete data-exposure risk to end users:

  • No game progress
  • No payment or subscription features are offered, and no related records exist

Ongoing Monitoring

The strengthened monitoring and alerting on the related infrastructure will remain in place. If Zeabur later releases material updates or new risks are identified, we will post a notice to this channel as soon as we can.