product · May 22, 2026
Karan Vaidya Provides Detailed Update on Composio Security Incident Affecting 0.3% of Connections
Share the canonical public link.
Karan Vaidya, a builder at Composio, shared a detailed update on May 22, 2026, about the security incident first disclosed the previous day. The post described how the attacker used LLM-generated patterns to exploit an internal agentic tool, leading to compromise of primarily GitHub tokens across roughly 5001 accounts plus limited others. Composio revoked every user's GitHub tokens preemptively, paused releases, verified SDK safety, and contacted affected users directly, with the post garnering 162 likes and over 62,000 views.