Blender MCP maintainer's GitHub account hijacked, with access restored two days later
Siddharth Ahuja, maintainer of the 25k-star blender-mcp server, reported on 2026-08-09 that his GitHub account was hacked and his ownership rights stripped, naming Blender MCP and Ableton MCP among the repositories taken away. On 2026-08-11 he posted that GitHub had banned the hacker and restored his account, and that the MCP servers themselves were not compromised. As of 2026-08-13 the repositories resolve back to his account.
Siddharth Ahuja, the maintainer of blender-mcp, a community MCP server for controlling Blender that he states has 25,000 GitHub stars, posted on 2026-08-09 that his GitHub account had been hacked and all of his ownership rights stripped. His disclosure named Blender MCP and Ableton MCP (2.6k stars) among the repositories taken away, along with personal projects.
On 2026-08-11 he posted an update: GitHub banned the hacker and restored access to his repositories and account. In the same update he stated that while the GitHub repository was taken over, "the actual MCP servers were NOT compromised", because the attacker "did not have the credentials to update the server python" package.
GitHub API records line up with that timeline. An organization named MCPBlender, describing itself as "AI-powered integrations for Blender, Ableton & creative tools via Model Context Protocol", was created on 2026-08-08, the day before the disclosure. As of 2026-08-13, a request for MCPBlender/blender-mcp resolves back to ahujasid/blender-mcp, the transfer-redirect behavior GitHub applies to a moved repository, and both blender-mcp and ableton-mcp show pushes dated 2026-08-11. No security advisory has been published on the repository, and the maintainer's account of what the attacker could and could not reach is the only public statement on impact so far.
This story is sourced from the maintainer's own verified X account and mechanical GitHub API records; the verification method is recorded as manual because there is no vendor advisory or incident page to cite.
How was this verified, and what are the sources?
Published · last verified · confidence 0.90.
- Maintainer's X post of 2026-08-09 - "URGENT: My Github got hacked and all my ownership rights were stripped. Repositories like Blender MCP (25k stars) and Ableton MCP (2.6k stars) along with personal projects I'm working on have been taken away." - accessed
- Maintainer's X profile - shows a 2026-08-11 update beginning "UPDATE: Github has banned the hacker and restored access for my repos and account", stating the repositories were taken over but "the actual MCP servers were NOT compromised" because the hacker "did not have the credentials to update the server python" package (post truncated in the logged-out view) - accessed
- GitHub REST API record for the MCPBlender organization - created 2026-08-08T11:33Z, described as "AI-powered integrations for Blender, Ableton & creative tools via Model Context Protocol" - accessed
- GitHub REST API request for MCPBlender/blender-mcp on 2026-08-13 - resolves to ahujasid/blender-mcp, showing the repository back under the maintainer's account after a transfer - accessed