Observed Signal · Oct 17, 2024 · Incident Report · Source: DEV Community · Impact: 2/5 · Sentiment: Neutral

Vercel Edge Timeout Caused 30-Minute Global API Outage

Executive Signal Summary

On October 17, 2024 at 14:22 UTC a global API experienced a full outage for 30 minutes after a Vercel Edge Function's execution timeout was misconfigured. A deployment changed the Edge Function maxDuration from 10 seconds to 1 second, which was below the average downstream response times (including PostgreSQL and third‑party auth calls), causing immediate 504 Gateway Timeout errors for all requests. The on‑call team identified the misconfiguration, rolled back the timeout to 10 seconds at 14:29 UTC, and restored service by 14:30 UTC. The postmortem lists contributing factors (no pre‑deployment validation, no staged rollouts, insufficient early alerting) and follow‑up actions including pre‑deployment checks against P95 historical execution times, staged rollouts with automatic rollback thresholds, new timeout alerting to Slack, updated deployment training, and a runbook for timeout incidents.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Operational postmortem about an application outage caused by edge compute configuration; relevant to engineering and reliability practices but not industry‑shifting.

SIGNAL RADAR

Track Vercel Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Incident occurred on 2024-10-17 at 14:22 UTC and lasted ~30 minutes.
  • A deployment reduced a Vercel Edge Function maxDuration from 10s to 1s, causing 504 Gateway Timeout errors.
  • Team rolled back the configuration at 14:29 UTC and service was confirmed healthy at 14:30 UTC.
  • Impact: 100% global API requests failed (estimated ~12,000 failed requests); no data loss reported.
  • Follow-ups: pre-deployment checks against 95th percentile execution times, staged rollouts (1% → 10% → 100%), timeout alerting to Slack, updated training and an incident runbook.

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Oct 17, 2024
Original Coverage Title: “Postmortem: A Vercel Edge Function Timeout Caused Our Global API to Fail for 30 Minutes”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Security BreachApr 20, 2026

Vercel hacked via Context AI; customer data stolen

Vercel confirmed a security breach on April 20, 2026, after attackers used an OAuth connection from a Context AI app to take over a Vercel employee’s Google account and access internal systems. The attackers claimed to have stolen customer API keys, source code and database data; Vercel said some credentials accessed were not encrypted. Vercel’s Next.js and Turbopack open-source projects were not affected. Vercel has contacted impacted customers and CEO Guillermo Rauch urged rotation of non-sensitive keys. Context AI acknowledged a March breach of its Context AI Office Suite consumer app and said some consumer OAuth tokens were likely compromised. A threat actor claimed association with the ShinyHunters group, which denies involvement; investigations are ongoing and Vercel warned of potential downstream impact across organizations.

Read assessment
Content delivery infrastructure / Mobile carrier DPI impactJul 8, 2026

Vercel Sites Fail on Some Mobile Networks; How to Fix

Developers have observed Vercel-hosted sites (including free *.vercel.app subdomains and custom domains pointing to Vercel) failing to load or timing out on certain mobile networks (e.g., MTN Zambia, Zed Mobile) while loading normally on others (e.g., Airtel). ICMP/ping to Vercel’s Anycast IP often succeeds, indicating routing is fine, but carrier-level Deep Packet Inspection (DPI) or broken optimization nodes inspect the TLS Server Name Indication (SNI) and drop or throttle the HTTPS handshake. Recommended mitigations include moving off the shared *.vercel.app subdomain to a custom domain, fronting traffic with a reverse proxy (Cloudflare) with DNS records set to “Proxied (Orange Cloud)”, and configuring Cloudflare’s SSL/TLS mode to Full (Strict) to avoid redirect/SSL loops.

Read assessment
IdentityMay 18, 2026

OAuth Token Theft Led to Vercel $2M Breach

A forgotten OAuth permission enabled attackers to access internal environment variables at Vercel in April 2026 and demand $2 million. The initial compromise began earlier after a Context.ai employee was infected with Lumma Stealer (February 2026), which stole active browser sessions and OAuth tokens. Hudson Rock's analysis links the chain of access from the AI startup to Vercel. The threat actor using the ShinyHunters persona claimed responsibility; Vercel confirmed a limited customer-impact breach, notified law enforcement, and published an OAuth Client ID as an indicator of compromise. The incident highlights risks from OAuth token abuse, infostealer malware, and forgotten third‑party app permissions across developer toolchains.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.