Skip to main content
  1. Home
  2. Computing
  3. News

A simple coding mistake is exposing API keys across thousands of websites

Security gaps that are easier to miss than you think

Add as a preferred source on Google
Computer, Electronics, Laptop
Adobe Stock Image

After analyzing 10 million webpages, researchers have found thousands of websites accidentally exposing sensitive API credentials, including keys linked to major services like Amazon Web Services, Stripe, and OpenAI.

This is a serious issue because APIs act as the backbone of the apps we use today. They allow websites to connect to services like payments, cloud storage, and AI tools, but they rely on digital keys to stay secure. Once exposed, API keys can allow anyone to interact with those services with malicious intent.

Sensitive API keys exposed across thousands of sites

According to TechXplore, the researchers identified 1,748 unique API credentials across nearly 10,000 webpages, tied to 14 major service providers. These leaks were not limited to obscure sites, with some appearing on platforms run by global banks and major software developers.

Recommended Videos

Around 84% of these leaks came from JavaScript files, which are easily accessible through a browser. This means the credentials were effectively sitting in publicly visible code.

Even more concerning is how long these keys remained exposed. Some were visible for up to 12 months, while a few rare cases showed credentials staying public for several years without detection.

So, what’s causing these leaks?

The study makes it clear that the problem does not lie with service providers like Amazon, Stripe, or OpenAI. Instead, the issue stems from how developers handle API keys.

In many cases, developers accidentally include private API credentials in the front-end code of a website, leaving it visible to anyone who knows where to look.

How to stop API keys from being exposed?

To prevent future leaks, the researchers suggest a few practical steps. Developers should scan the live version of their websites, and not just private code, to catch exposed keys.

With the rise of vibecoding, companies need stricter rules for automated website-building tools that handle sensitive data during deployment. This is also why platforms like Lovable have started adding safe browsing tools to protect users from poorly vibecoded websites.

Meanwhile, service providers need to improve detection systems to flag exposed keys the moment they appear online. Although responsible disclosure helped reduce some of these leaks, the scale of the issue remains significant.

Recent reports have also shown how simply visiting a website can expose your device to serious risks, highlighting how fragile web security can be for everyday internet users.

Manisha Priyadarshini
Manisha Priyadarshini is a tech and entertainment writer with over nine years of editorial experience.
Gemini will now take notes for you in Google Meet for you, if you the minimum $20 AI tax
Yet another Google subscription just dropped for Gemini
Google Meet Take Notes for me Gemini

Google has just released a useful Gemini feature, which you can try if you are a paying member of course. The company is now bringing "Take notes for me" for Gemini, which will be available in Google Meet for Google AI Pro and Google AI Ultra subscribers, along with eligible Workspace business customers.

For personal users, the feature starts with Google AI Pro, which costs $19.99 per month in the US. In other words, Gemini can now take your Google Meet notes, provided you pay the minimum AI tax.

Read more
After iPad Pro and MacBook Pro, the iMac could be the next in line for an OLED screen upgrade
iMac with M4

The iPhone got an OLED panel in 2017, while the iPad Pro followed in 2024. Even the MacBook Pro is expected to follow later this year or early next year. But what about the iMac?

According to TrendForce, the iMac could get an OLED upgrade. There's no timeline yet, but the direction is clear. Apple wants to replace its current display technologies with OLED, raising the bar for color quality for both regular users and professionals.

Read more
This $1,299 gaming PC wants to be a Steam Machine without waiting for Valve
Valve’s Steam Machine dream is already real in MetaPC's new prebuilt
MetaPC's Steamroller is a new Steam Machine rival

Valve’s Steam Machine may be the face of SteamOS, but the platform isn't exclusive to it. A big announcement after Steam Machine's unveiling was that SteamOS would be arriving on systems outside of the new hybrid console. Now, MetaPCs is one of the first to take advantage of this by opening the preorders for the Steamroller, a new prebuilt gaming desktop that ships with SteamOS installed by default.

Though Steamroller is not trying to be a tiny console-like cube. It is a normal desktop PC with standard parts and a real upgrade path. The system costs $1,299 and is listed with a preorder date of July 3, 2026.

Read more