Observed Signal · Oct 17, 2024 · Incident Report · Source: DEV Community · Impact: 2/5 · Sentiment: Neutral
Vercel Edge Timeout Caused 30-Minute Global API Outage
On October 17, 2024 at 14:22 UTC a global API experienced a full outage for 30 minutes after a Vercel Edge Function's execution timeout was misconfigured. A deployment changed the Edge Function maxDuration from 10 seconds to 1 second, which was below the average downstream response times (including PostgreSQL and third‑party auth calls), causing immediate 504 Gateway Timeout errors for all requests. The on‑call team identified the misconfiguration, rolled back the timeout to 10 seconds at 14:29 UTC, and restored service by 14:30 UTC. The postmortem lists contributing factors (no pre‑deployment validation, no staged rollouts, insufficient early alerting) and follow‑up actions including pre‑deployment checks against P95 historical execution times, staged rollouts with automatic rollback thresholds, new timeout alerting to Slack, updated deployment training, and a runbook for timeout incidents.
Operational postmortem about an application outage caused by edge compute configuration; relevant to engineering and reliability practices but not industry‑shifting.
Track Vercel Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Incident occurred on 2024-10-17 at 14:22 UTC and lasted ~30 minutes.
- A deployment reduced a Vercel Edge Function maxDuration from 10s to 1s, causing 504 Gateway Timeout errors.
- Team rolled back the configuration at 14:29 UTC and service was confirmed healthy at 14:30 UTC.
- Impact: 100% global API requests failed (estimated ~12,000 failed requests); no data loss reported.
- Follow-ups: pre-deployment checks against 95th percentile execution times, staged rollouts (1% → 10% → 100%), timeout alerting to Slack, updated training and an incident runbook.
Connected Companies & Entities
1 Entity mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Vercel hacked via Context AI; customer data stolen
Vercel confirmed a security breach on April 20, 2026, after attackers used an OAuth connection from a Context AI app to take over a Vercel employee’s Google account and access internal systems. The attackers claimed to have stolen customer API keys, source code and database data; Vercel said some credentials accessed were not encrypted. Vercel’s Next.js and Turbopack open-source projects were not affected. Vercel has contacted impacted customers and CEO Guillermo Rauch urged rotation of non-sensitive keys. Context AI acknowledged a March breach of its Context AI Office Suite consumer app and said some consumer OAuth tokens were likely compromised. A threat actor claimed association with the ShinyHunters group, which denies involvement; investigations are ongoing and Vercel warned of potential downstream impact across organizations.
Vercel Sites Fail on Some Mobile Networks; How to Fix
Developers have observed Vercel-hosted sites (including free *.vercel.app subdomains and custom domains pointing to Vercel) failing to load or timing out on certain mobile networks (e.g., MTN Zambia, Zed Mobile) while loading normally on others (e.g., Airtel). ICMP/ping to Vercel’s Anycast IP often succeeds, indicating routing is fine, but carrier-level Deep Packet Inspection (DPI) or broken optimization nodes inspect the TLS Server Name Indication (SNI) and drop or throttle the HTTPS handshake. Recommended mitigations include moving off the shared *.vercel.app subdomain to a custom domain, fronting traffic with a reverse proxy (Cloudflare) with DNS records set to “Proxied (Orange Cloud)”, and configuring Cloudflare’s SSL/TLS mode to Full (Strict) to avoid redirect/SSL loops.
OAuth Token Theft Led to Vercel $2M Breach
A forgotten OAuth permission enabled attackers to access internal environment variables at Vercel in April 2026 and demand $2 million. The initial compromise began earlier after a Context.ai employee was infected with Lumma Stealer (February 2026), which stole active browser sessions and OAuth tokens. Hudson Rock's analysis links the chain of access from the AI startup to Vercel. The threat actor using the ShinyHunters persona claimed responsibility; Vercel confirmed a limited customer-impact breach, notified law enforcement, and published an OAuth Client ID as an indicator of compromise. The incident highlights risks from OAuth token abuse, infostealer malware, and forgotten third‑party app permissions across developer toolchains.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
