Technologist Mag
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
Motorola leak reveals the upcoming Razr 70 Ultra, and it doesn’t want to change one bit

Motorola leak reveals the upcoming Razr 70 Ultra, and it doesn’t want to change one bit

27 March 2026
Super Meat Boy 3D Brings Precision Platformer To A New Dimension This Month

Super Meat Boy 3D Brings Precision Platformer To A New Dimension This Month

26 March 2026
Anduril Wants to Own the Future of War Tech. Mishaps, Delays, and Challenges Abound

Anduril Wants to Own the Future of War Tech. Mishaps, Delays, and Challenges Abound

26 March 2026
Dating Apps Are Evolving Beyond the Swipe To AI Agents 

Dating Apps Are Evolving Beyond the Swipe To AI Agents 

26 March 2026
Stranger Than Heaven Will Take Place Across Five Time Periods, Deep-Dive Presentation Arriving This May

Stranger Than Heaven Will Take Place Across Five Time Periods, Deep-Dive Presentation Arriving This May

26 March 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Technologist Mag
SUBSCRIBE
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release
Technologist Mag
Home » A simple coding mistake is exposing API keys across thousands of websites
Tech News

A simple coding mistake is exposing API keys across thousands of websites

By technologistmag.com26 March 20262 Mins Read
A simple coding mistake is exposing API keys across thousands of websites
Share
Facebook Twitter Reddit Telegram Pinterest Email

After analyzing 10 million webpages, researchers have found thousands of websites accidentally exposing sensitive API credentials, including keys linked to major services like Amazon Web Services, Stripe, and OpenAI.

This is a serious issue because APIs act as the backbone of the apps we use today. They allow websites to connect to services like payments, cloud storage, and AI tools, but they rely on digital keys to stay secure. Once exposed, API keys can allow anyone to interact with those services with malicious intent.

Sensitive API keys exposed across thousands of sites

According to TechXplore, the researchers identified 1,748 unique API credentials across nearly 10,000 webpages, tied to 14 major service providers. These leaks were not limited to obscure sites, with some appearing on platforms run by global banks and major software developers.

Around 84% of these leaks came from JavaScript files, which are easily accessible through a browser. This means the credentials were effectively sitting in publicly visible code.

Even more concerning is how long these keys remained exposed. Some were visible for up to 12 months, while a few rare cases showed credentials staying public for several years without detection.

So, what’s causing these leaks?

The study makes it clear that the problem does not lie with service providers like Amazon, Stripe, or OpenAI. Instead, the issue stems from how developers handle API keys.

In many cases, developers accidentally include private API credentials in the front-end code of a website, leaving it visible to anyone who knows where to look.

How to stop API keys from being exposed?

To prevent future leaks, the researchers suggest a few practical steps. Developers should scan the live version of their websites, and not just private code, to catch exposed keys.

graphic image of cybersecurity

With the rise of vibecoding, companies need stricter rules for automated website-building tools that handle sensitive data during deployment. This is also why platforms like Lovable have started adding safe browsing tools to protect users from poorly vibecoded websites.

Meanwhile, service providers need to improve detection systems to flag exposed keys the moment they appear online. Although responsible disclosure helped reduce some of these leaks, the scale of the issue remains significant.

Recent reports have also shown how simply visiting a website can expose your device to serious risks, highlighting how fragile web security can be for everyday internet users.

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleGhost Of Tsushima And Yōtei’s Legends’ Co-op Modes Are Experiments According To Lead Designer
Next Article Anthropic Supply-Chain Risk Designation Halted By Judge

Related Articles

Motorola leak reveals the upcoming Razr 70 Ultra, and it doesn’t want to change one bit

Motorola leak reveals the upcoming Razr 70 Ultra, and it doesn’t want to change one bit

27 March 2026
Anduril Wants to Own the Future of War Tech. Mishaps, Delays, and Challenges Abound

Anduril Wants to Own the Future of War Tech. Mishaps, Delays, and Challenges Abound

26 March 2026
Dating Apps Are Evolving Beyond the Swipe To AI Agents 

Dating Apps Are Evolving Beyond the Swipe To AI Agents 

26 March 2026
This Groundbreaking Omega Watch’s Accuracy Is Calibrated Using Sound

This Groundbreaking Omega Watch’s Accuracy Is Calibrated Using Sound

26 March 2026
Artemis II crew preps for lunar orbit – and Orion’s cosmic commode

Artemis II crew preps for lunar orbit – and Orion’s cosmic commode

26 March 2026
How to Buy Ethical and Eco-Friendly Electronics (2026)

How to Buy Ethical and Eco-Friendly Electronics (2026)

26 March 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Don't Miss
Super Meat Boy 3D Brings Precision Platformer To A New Dimension This Month

Super Meat Boy 3D Brings Precision Platformer To A New Dimension This Month

By technologistmag.com26 March 2026

Super Meat Boy 3D is set to bring the classic 2D series into the 3D…

Anduril Wants to Own the Future of War Tech. Mishaps, Delays, and Challenges Abound

Anduril Wants to Own the Future of War Tech. Mishaps, Delays, and Challenges Abound

26 March 2026
Dating Apps Are Evolving Beyond the Swipe To AI Agents 

Dating Apps Are Evolving Beyond the Swipe To AI Agents 

26 March 2026
Stranger Than Heaven Will Take Place Across Five Time Periods, Deep-Dive Presentation Arriving This May

Stranger Than Heaven Will Take Place Across Five Time Periods, Deep-Dive Presentation Arriving This May

26 March 2026
This Groundbreaking Omega Watch’s Accuracy Is Calibrated Using Sound

This Groundbreaking Omega Watch’s Accuracy Is Calibrated Using Sound

26 March 2026
Technologist Mag
Facebook X (Twitter) Instagram Pinterest
  • Privacy
  • Terms
  • Advertise
  • Contact
© 2026 Technologist Mag. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.