Company · Chapter 10 of 16·2 min read
The Day We Found a Credential Leaking From Our Own Builds
A database credential had been sitting inside every public download of our own CLI, desktop app, and bots app for weeks. Here's what we found, what we did in the hours after, and what changed in how we build.

Listen to this story
Not something someone reported to us
This wasn't a bug bounty email or a stranger's DM. It turned up during ordinary build work, while touching something unrelated — the kind of finding that's genuinely worse to make late than to make at all, because by the time you find it, it's usually already been sitting there a while.
A credential that never should have shipped
A database credential meant only for internal services had been getting baked directly into publicly downloadable builds — the CLI, the desktop app, the bots app, across every platform we ship for. Not a theoretical exposure. Confirmed live, downloadable from our own site, across every recent build, for weeks.
What we did in the hours after
Every affected download was pulled from the public site immediately, before anything else. The exposed credentials were rotated the same session, and the old ones were confirmed dead against the live database — not assumed, checked.
Fixing the actual cause, not just the symptom
Rotating a credential fixes today. It doesn't fix the process that put it there. Every build and staging script that had been embedding it was rewritten to stop doing that entirely, and every other secret those same scripts had hardcoded directly in source got moved to one file, kept out of git, so the next rotation is a single edit instead of a search across six different scripts hoping you found all of them.
The rotation closes the exposure. The process fix is what stops it from happening the same way twice.
Why we're telling you this
A small team shipping fast is going to make real mistakes — that's not a hypothetical, it's just true. The part that's actually within our control is what happens in the hours after one gets found: whether it gets fixed quietly and hoped nobody notices, or fixed and said out loud. We'd rather you trust Nia because we're straightforward about the second part, not because you assume the first part never happens.
