Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: secrets-exposure (2 articles)Clear

Stolen AI API key from an exposed app burned through 600,000 dollars in credits

The AI evaluation nonprofit METR disclosed that attackers stole a model-provider API key and ran up about 600,000 dollars worth of inference credits over three weeks. The key sat on a researcher's personal cloud instance that was meant to be protected by a Google login but, due to a fail-open authentication bug in a quickly built app, was actually publicly reachable. After finding it, the attacker prompted the AI agent running there to reveal its provider API key, added an SSH key for persistence, and consumed credits on public models. The abuse went unnoticed for a while because METR routinely runs high-token evaluations and had no spending caps on the key.

Check
Keep provider API keys off personal and non-organizational infrastructure, add spend caps and usage alerts to every key, and make sure agents cannot be prompted into revealing the credentials they hold.
Affected
Organizations with AI provider API keys on loosely protected or personal infrastructure; a stolen key with no spending cap can rack up costly inference, and exposed agents may leak keys when prompted.
Fix
Store keys in a secrets manager, scope and cap them, monitor for anomalous token spend, avoid embedding retrievable keys in agent environments, and verify quickly built apps fail closed, not open.

Truffle Security finds hundreds of leaked AWS keys still fully controlling accounts

Researchers at Truffle Security reported that after four years of collecting leaked Amazon Web Services keys, they found 768 that still grant full control over a company's cloud account, with a median age of about five years. The keys were exposed in places like public code and configuration and were never rotated, so they remain live long after the people who created them have likely forgotten them. A single valid key with broad permissions can let an attacker read data, spin up resources, and move through a cloud environment. The finding is a reminder that leaked long-lived credentials remain one of the most durable and overlooked paths into cloud accounts.

Check
Scan code, configuration, and logs for exposed AWS keys, revoke and rotate any long-lived keys you find, and move toward short-lived credentials and roles instead of static access keys.
Affected
Organizations with old, long-lived AWS access keys exposed in code or configuration and never rotated; an attacker who finds a still-valid key can gain full control of the account it belongs to.
Fix
Replace static keys with temporary credentials and roles, enforce rotation and least privilege, add automated secret scanning across repositories and history, and monitor for use of old or unexpected keys.