Researchers scan 10 million websites and discover thousands of exposed API keys discreetly providing access to cloud systems and critical infrastructure.


  • Thousands of exposed API keys discreetly grant access to critical systems
  • Public web pages contain credentials that unlock cloud and payment services
  • Developers unknowingly leave sensitive API tokens embedded in live websites

Security researchers from Stanford University, UC Davis and TU Delft say sensitive API credentials are found openly on thousands of public web pages, with very little protection.

According to a preprint version of the study on arXiv, researchers analyzed 10 million web pages and identified 1,748 valid credentials exposed on nearly 10,000 pages.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top