CrowdSec

Sep 2026 · Graded Attested · Technology and Software · Beyond the filings
CrowdSecSep 2026
Not yet quantified
AAttested
CrowdSec's source code, roughly 300 repositories, 170 of them private, sat exposed after the May 2026 TanStack supply chain attack. Most likely culprit? A single compromised API key. That one key reached across the SaaS console, AWS operations, connectors, and automation scripts: one credential, one blast radius. CrowdSec states confidently that the source code can't be used to cause harm because it can't be used outside of its context. Not finding the leak of the source code for several months does make those reassurances seem a bit bold, given the circumstances.
Technology and Software
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
About this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.
← The complete Beyond the Filings ledger ← Back to the index