logo

The Rising Risk Of Exposed ChatGPT API Keys

ID: ef15d2a8-b707-5be7-aa23-de8abd54534b

STIX ID: report--ef15d2a8-b707-5be7-aa23-de8abd54534b

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2026-02-12

Date Updated: 2026-07-16

...
...

CRIL discovered widespread, systematic exposure of ChatGPT/OpenAI API keys—over 5,000 public GitHub repositories and around 3,000 live websites—leading to easy harvesting and abuse by threat actors for inference fraud, phishing, malware development, and billing theft; the report emphasizes that AI API keys are production secrets, outlines attacker monetization and detection gaps, and provides prescriptive mitigations (remove keys from client code, enforce secret scanning, apply least privilege, and monitor AI usage).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.