Strix scanned Baseten for safety and got admin access to its production GitHub in 25 minutes
We got admin access to Baseten's production GitHub in 25 minutes
Security firm Strix pointed its autonomous hacking agent at *.baseten.co before trusting the inference provider with customer data. The agent found a public Harbor registry, pulled a March 2023 image, and extracted a still-valid GitHub personal access token from the Docker build history. The token belonged to basetenbot and held admin and push access to basetenlabs/baseten (the main product repo), the flux-cd GitOps repo, and the homebrew-tap, plus read/write on several private repos. Baseten’s security team confirmed the issue as critical, locked the registry, and rotated the token by the next afternoon. The post does not say whether any customer data was exposed.
Why it matters: A security disclosure with a concrete attack chain, timeline, and permission level — not a proof-of-concept. HKR all hit, but this is a single incident, not an industry shift, so it lands in the 78-84 band. Strix is both the discloser and the beneficiary, so I'm docking a few ...