Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
Gorgeously Animated Platformer The Eternal Life Of Goldman Gets New Trailer And Will Launch On Game Pass

Gorgeously Animated Platformer The Eternal Life Of Goldman Gets New Trailer And Will Launch On Game Pass

27 March 2026
Dating Apps Are Evolving Beyond the Swipe To AI Agents 

Dating Apps Are Evolving Beyond the Swipe To AI Agents 

27 March 2026
Anthropic Supply-Chain-Risk Designation Halted by Judge

Anthropic Supply-Chain-Risk Designation Halted by Judge

27 March 2026
Facebook X (Twitter) Instagram
Just In
  • Gorgeously Animated Platformer The Eternal Life Of Goldman Gets New Trailer And Will Launch On Game Pass
  • Dating Apps Are Evolving Beyond the Swipe To AI Agents 
  • Anthropic Supply-Chain-Risk Designation Halted by Judge
  • Ghost Of Tsushima And Yōtei’s Legends’ Co-op Modes Are Experiments According To Lead Designer
  • A simple coding mistake is exposing API keys across thousands of websites
  • Review: Eufy Omni C28
  • Hades II And Dispatch Are Coming To Xbox Soon
  • iOS 26.4 adds ChatGPT to you car’s infotainment screen
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » A simple coding mistake is exposing API keys across thousands of websites
News

A simple coding mistake is exposing API keys across thousands of websites

News RoomBy News Room27 March 20262 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
A simple coding mistake is exposing API keys across thousands of websites
Share
Facebook Twitter LinkedIn Pinterest Email

After analyzing 10 million webpages, researchers have found thousands of websites accidentally exposing sensitive API credentials, including keys linked to major services like Amazon Web Services, Stripe, and OpenAI.

This is a serious issue because APIs act as the backbone of the apps we use today. They allow websites to connect to services like payments, cloud storage, and AI tools, but they rely on digital keys to stay secure. Once exposed, API keys can allow anyone to interact with those services with malicious intent.

Sensitive API keys exposed across thousands of sites

According to TechXplore, the researchers identified 1,748 unique API credentials across nearly 10,000 webpages, tied to 14 major service providers. These leaks were not limited to obscure sites, with some appearing on platforms run by global banks and major software developers.

Around 84% of these leaks came from JavaScript files, which are easily accessible through a browser. This means the credentials were effectively sitting in publicly visible code.

Even more concerning is how long these keys remained exposed. Some were visible for up to 12 months, while a few rare cases showed credentials staying public for several years without detection.

So, what’s causing these leaks?

The study makes it clear that the problem does not lie with service providers like Amazon, Stripe, or OpenAI. Instead, the issue stems from how developers handle API keys.

In many cases, developers accidentally include private API credentials in the front-end code of a website, leaving it visible to anyone who knows where to look.

How to stop API keys from being exposed?

To prevent future leaks, the researchers suggest a few practical steps. Developers should scan the live version of their websites, and not just private code, to catch exposed keys.

graphic image of cybersecurity

With the rise of vibecoding, companies need stricter rules for automated website-building tools that handle sensitive data during deployment. This is also why platforms like Lovable have started adding safe browsing tools to protect users from poorly vibecoded websites.

Meanwhile, service providers need to improve detection systems to flag exposed keys the moment they appear online. Although responsible disclosure helped reduce some of these leaks, the scale of the issue remains significant.

Recent reports have also shown how simply visiting a website can expose your device to serious risks, highlighting how fragile web security can be for everyday internet users.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleReview: Eufy Omni C28
Next Article Ghost Of Tsushima And Yōtei’s Legends’ Co-op Modes Are Experiments According To Lead Designer

Related Articles

Dating Apps Are Evolving Beyond the Swipe To AI Agents 
News

Dating Apps Are Evolving Beyond the Swipe To AI Agents 

27 March 2026
Anthropic Supply-Chain-Risk Designation Halted by Judge
News

Anthropic Supply-Chain-Risk Designation Halted by Judge

27 March 2026
Review: Eufy Omni C28
News

Review: Eufy Omni C28

27 March 2026
iOS 26.4 adds ChatGPT to you car’s infotainment screen
News

iOS 26.4 adds ChatGPT to you car’s infotainment screen

26 March 2026
How Trump’s Plot to Grab Iran’s Nuclear Fuel Would Actually Work
News

How Trump’s Plot to Grab Iran’s Nuclear Fuel Would Actually Work

26 March 2026
I transferred all my chats from other AI apps to Gemini — and it works flawlessly
News

I transferred all my chats from other AI apps to Gemini — and it works flawlessly

26 March 2026
Demo
Top Articles
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 2024132 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024111 Views
Costco partners with Electric Era to bring back EV charging in the U.S.

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 2024100 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Review: Eufy Omni C28 News

Review: Eufy Omni C28

News Room27 March 2026
Hades II And Dispatch Are Coming To Xbox Soon Gaming

Hades II And Dispatch Are Coming To Xbox Soon

News Room26 March 2026
iOS 26.4 adds ChatGPT to you car’s infotainment screen News

iOS 26.4 adds ChatGPT to you car’s infotainment screen

News Room26 March 2026
Most Popular
The Spectacular Burnout of a Solar Panel Salesman

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025137 Views
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 2024132 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024111 Views
Our Picks
Ghost Of Tsushima And Yōtei’s Legends’ Co-op Modes Are Experiments According To Lead Designer

Ghost Of Tsushima And Yōtei’s Legends’ Co-op Modes Are Experiments According To Lead Designer

27 March 2026
A simple coding mistake is exposing API keys across thousands of websites

A simple coding mistake is exposing API keys across thousands of websites

27 March 2026
Review: Eufy Omni C28

Review: Eufy Omni C28

27 March 2026

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2026 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.