vulnerability management

8,000+ ChatGPT API keys exposed across GitHub & production sites

March 23, 2026
8,000+ ChatGPT API keys exposed across GitHub and live sites reveal a growing “vibe coding” risk. Learn how leaked AI credentials are exploited, the financial impact, and how to prevent exposure with proper secrets management and remediation.

A recent discovery by Cyble Research should serve as a wake-up call for network security teams and engineering leaders everywhere. Security researchers found over 5,000 public GitHub repositories and 3,000 live production websites actively exposing hardcoded ChatGPT API keys.

This isn't just a collection of isolated developer mistakes. It represents a systemic breakdown in modern network and repository security.

As organizations scramble to integrate generative AI, basic security hygiene is falling by the wayside. A major driver is "vibe coding" - a speed-over-security culture where the rush to ship generative AI features leads teams to skip standard security protocols entirely.

In this modern gold rush, sensitive AI credentials get treated like disposable test props, rather than what they actually are: critical production secrets.

The anatomy of an AI credential leak

A leaked API key's path to misuse usually starts innocently, during the rapid prototyping phase of vibe coding. A developer eager to test a new ChatGPT integration hardcodes an API key into their local testing environment.

In the rush to ship, that temporary shortcut gets forgotten. It ends up in client-side JavaScript or a public GitHub commit. Once that code is pushed, the security perimeter is effectively breached.

The timeline between exposure and exploitation is short. Automated scanners and bots constantly scrape public repositories and live websites, looking for exactly these kinds of strings. As a result, exposed credentials are often harvested within hours - sometimes minutes - of a single insecure commit.

Once a key is scavenged, the technical barrier for attackers is low. Stolen OpenAI tokens are quickly weaponized to fuel a range of downstream criminal activity. Here's how attackers typically exploit these exposed keys:

  • Massive phishing content generation: Threat actors use compromised enterprise AI access to draft convincing, localized phishing emails at scale.
  • Automated scam scripts: Scavenged keys power malicious chatbots designed to defraud users or distribute malware.
  • Social engineering lures: High-tier AI access is used to create deepfakes or tailored textual lures aimed at specific corporate targets.

The new class of shadow IT risk

The rise of vibe coding has introduced a new challenge for CTOs and CISOs: "Shadow AI." Rogue, unvetted AI integration experiments - often driven by individual developers or siloed teams - frequently bypass standard network security and procurement vetting.

This creates large, unmonitored blind spots across the enterprise. Security teams end up with no visibility into where and how AI is actually being used on their own networks.

The financial toll of unchecked AI service abuse

The financial fallout from unchecked service abuse at scale is severe. When threat actors get their hands on stolen, high-tier corporate keys, they don't hesitate to run high-volume inference workloads under the victim's billing account.

This drains billing accounts and rapidly exhausts API credits - leading to unpredictable, potentially ruinous cloud bills that can blow up an IT budget overnight.

The persistent threat of client-side exposures

This threat is especially persistent when it comes to the 3,000 live production sites identified in the Cyble report. Client-side exposures are particularly dangerous. Unlike a repository leak, which can be rolled back or patched quickly, website-based exposures continuously leak secrets to anyone inspecting the application's source code - acting as a permanent, silent backdoor into the company's AI resources.

Compromised code repositories as network pivot points

When public code repositories are compromised, the broader network security implications get serious fast. Stolen API keys can serve as a highly privileged pivot point for attackers. Using them, bad actors can potentially access internal corporate data fed into the AI, manipulate proprietary datasets, or probe deeper into the organization's wider cloud infrastructure.

Why AI tokens are the new master keys

It helps to contrast traditional cloud access keys with modern AI API keys. Traditional keys often have narrowly defined scopes. AI tokens, by contrast, are essentially master keys to powerful inference engines and vast computational billing resources.

They hold immense power, and need the same rigor, visibility, and strict access controls as core enterprise identity credentials.

Defending code repositories and networks in the AI era

To defend against these threats, VPs of Engineering need a clear technical roadmap to permanently eliminate secrets from client-side code and public-facing assets. This means shifting away from hardcoding, and prioritizing robust secrets management platforms and dynamic environment variables built for fast-paced AI workflows.

AI systems, whether agentic or LLM-based, are inherently insecure right now because they don't distinguish between execution code and input data. That means code repositories need proactive, secure-at-inception guardrails. Organizations must push for, and strictly enforce, mechanisms that stop leaks before they happen. Engineering leaders should deploy the following controls:

  • Pre-commit linting: Developers resolve potential secret exposures locally, before code is even ready for a commit.
  • Automated secret-scanning tools: Continuous repository scanning flags and alerts on any accidental key exposure immediately.
  • Hard Git hooks: Strict pre-receive hooks let organizations reject any commit containing strings that match known credential formats.

Beyond the codebase, organizations need access control and network containment policies built specifically for AI integrations. Development teams should apply the principle of least privilege to all AI keys.

Where possible, enforce strict IP allowlisting to restrict API calls to known corporate servers. Configure hard usage quotas too, to limit the damage if a key is ever compromised.

Fostering a culture of secure innovation with Vicarius

Shifting organizational culture away from reckless "vibe coding," without stifling innovation, requires real, systemic changes. Chief among these: comprehensive asset discovery and real-time inventory tracking.

Organizations can't secure what they can't see. Full visibility over the network is what brings rogue AI experiments and shadow IT back under central, unified governance.

This raises a critical question: how can organizations secure rapid AI deployments when traditional remediation cycles and code rollbacks are too slow?

vRx by Vicarius addresses this directly. It uses AI-driven, contextual risk prioritization to cut through alert noise, so teams can focus on active threats instead of theoretical vulnerabilities. It also uses built-in scripting alongside in-memory Patchless Protection to instantly neutralize exposed credentials and vulnerable integrations - no source code change or system reboot required. By automating these immediate defenses, we help turn security from a development bottleneck into a competitive edge.

From vulnerable experimentation to resilient execution

Recent events make it clear: the current AI gold rush has created a massive, easily exploitable credential problem. The era of vibe coding has prioritized speed over safety, and the cost of that trade-off is now obvious.

Executives need to recognize that protecting code repositories, and treating AI credentials as highly sensitive production secrets, is no longer optional. It's the baseline for safe, sustainable innovation.

Don't wait for an exposed token to drain your resources or compromise your network. Book a personal demo of vRx to see firsthand how you can automatically discover, prioritize, and remediate exposed API keys, vulnerable assets, and shadow AI risks - before they fuel the next major breach.

Related resources:
CVE research

vRx product tour

Sagy Kratu

Sr. Product Marketing Manager

Subscribe for more

Get more infosec news and insights.

Related articles

1000+ members

Turn security converstains into remediation actions