Skip to content
Strix Discovers Critical GitHub Token Exposure at Baseten

Strix Discovers Critical GitHub Token Exposure at Baseten

First seen 16 Sep 2026, 16:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 18:53 UTC
  • Strix found a live GitHub token with admin rights in Baseten's infrastructure.
  • The token had been active for over three years, granting access to sensitive repositories.
  • Baseten's security team responded quickly, rotating the token within a day.

Security startup Strix identified a critical vulnerability in Baseten's infrastructure, discovering a live GitHub personal access token with repository-level admin rights within 25 minutes. The token, associated with the 'basetenbot' account, had been active since March 2023 and provided access to several private repositories, including customer-specific ones. Strix performed this scan as part of their due diligence before using Baseten's services. Upon discovery, Baseten's security team promptly confirmed the issue, locked down the affected project, and rotated the token within a day. This incident highlights the potential vulnerabilities in cloud infrastructure providers, particularly in the AI neocloud sector. Strix's autonomous hacking agent, Strix, utilized reconnaissance techniques to uncover the token through a public Harbor container registry associated with Baseten. The incident raises concerns about the security practices of neocloud providers, emphasizing the need for thorough vendor assessments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-03-01
GitHub token created
A personal access token for the 'basetenbot' account was generated, allowing extensive access to Baseten's repositories.
News.Ycombinator
2026-07-13
Token vulnerability discovered
Strix's autonomous agent found the active GitHub token during a security scan of Baseten's infrastructure.
Techzine.Eu
2026-07-13
Baseten notified of the issue
Strix reported the vulnerability to Baseten, prompting immediate action from their security team.
Techzine.Eu
2026-07-14
Token rotated
Baseten's security team confirmed the issue and rotated the compromised token within 24 hours.
News.Ycombinator
2026-09-15
Incident reported publicly
Strix published a detailed account of the incident, highlighting the vulnerability and Baseten's response.
News.Ycombinator

More articles in this cluster (3)

Following this threat?

Track Baseten in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed