CrowdSec says its private source code — including the console software behind its SaaS business, AWS routines, connectors and automations — was leaked online in May 2026. The security company announced the breach on September 16.
What Was Leaked
CrowdSec’s codebase splits into two parts. One is public by design: the Security Engine, which is free open-source software hosted on GitHub. That code is “out of scope” for this incident, according to the company. The other half is private, and it is that private code that escaped.
The leaked material includes:
- Source code for the SaaS console
- AWS Cloud routines
- Connectors and automations
CrowdSec says the leak does not include any client data, login credentials, names, organizations or personally identifiable information (PII). The company also says it does not store client logs. Its statement emphasizes that the impact is limited to CrowdSec itself.
How the Breach Happened
CrowdSec points to the Tanstack component as the likely vector for the leak. The company says the component was used in its organization in May 2026 and appears to have been backdoored to extract an API key with authorization to read the private codebase.
The leak was only exploitable during a short window in May. Since then, CrowdSec has rotated all required tokens and credentials to prevent further incidents.
The company’s statement describes the stolen API key as the token used by its CI/CD component itself. There is no confirmation of “other file contained” or “internal development material,” since all the code is published in the repositories.
Why the Company Says the Damage Is Limited
CrowdSec argues that the leaked code cannot harm the company directly. The firm’s efficiency depends on its network effect and size, which code alone cannot replicate. Regular audits of the SaaS source code mean the leakage should not pose an immediate threat.
Most of the leaked code has evolved significantly over the four months between the breach and the announcement. CrowdSec says it will closely monitor for any abnormal activity.
The company also doubts the code can be used elsewhere. It only interacts with CrowdSec’s data and tools and cannot really be leveraged in another context, according to the statement.
What This Means for Developers
For the broader developer community, the incident raises questions about dependency management. CrowdSec’s description of the Tanstack compromise suggests a component that was trusted became a vector for theft.
The company’s response has been swift. It rotated tokens and credentials after discovering the breach. That action closes off the path the attacker took, even if the code itself remains exposed.
CrowdSec says it will keep stakeholders updated as the investigation continues. The company’s thanks to Fuites Infos for reporting the issue professionally adds a note of cooperation to a difficult situation.
| Event | Date |
|---|---|
| Tanstack component exploited | May 2026 |
| API key extracted | May 2026 |
| Code leaked | May 2026 |
| Breach discovered | September 16 |
| Statement published | September 16 |
Key facts:
– Private source code leaked in May 2026
– Breach announced September 16
– No client data, credentials or PII exposed
– Tanstack identified as likely vector
– All tokens rotated after discovery
The breach is notable for the scale of the exposed codebase and the speed of the response. CrowdSec moved fast, rotated tokens and kept its public statements transparent.
CrowdSec’s own assessment is measured: the code has value but cannot harm the company directly, and the breach vector appears closed. For now, the company is monitoring for further signs of trouble.
Source material: “CrowdSec Source Code Leak,” crowdsec.net.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

