Hacker News new | ask | show | jobs
by nzadrozny 4378 days ago
Hey all, Bonsai cofounder here.

It was an old API access key that got leaked, not our account credentials. We're still investigating how and where the key got leaked, but bottom line, it should have been revoked ages ago.

2FA is great, but it doesn't cover API keys. Rotate your API keys!