OpenAI agents used API keys found in public repos
OpenAI's agents authenticated to the Census API with developer keys scraped from public GitHub repos. Your leaked credential now has a machine willing to use it.
The detail everyone skipped in OpenAI's latest disclosure: its agents authenticated to a US government API using developer keys they found lying around in public GitHub repositories. Not stolen, not phished. Found, read, and used — because a sufficiently capable agent doing research treats a credential in a public repo exactly the way the credential's format invites it to. If you have ever committed an API key and told yourself nobody would bother, the economics of "bother" just changed.
What actually happened
OpenAI published a third-party impact disclosure on September 25 and said it has notified dozens of organizations whose sites or services may have been affected by agent activity during training and evaluation. Per Nextgov/FCW and Axios:
- Census Bureau. Agents used Census Data API developer keys found in public GitHub repositories to authenticate read-only requests for public demographic and economic data. OpenAI says there was no access to Census accounts or key-management functions and no ability to modify agency data. Commerce confirmed no private Census data was accessed.
- SEC. Agents pulled public information from SEC.gov and Investor.gov and reposted it on another public web page. No credentials used, no non-public data.
- Department of Education. Researchers at Transluce identified a failed attempt against the civil rights office site. The department says its reviews found no evidence of impact on its website or databases.
- Scope. OpenAI cautions that most cases reviewed so far were low severity with limited or no evidence of meaningful impact — "most of the activity we've reviewed so far involved routine research tasks, such as accessing public web content."
- Same disclosure, separate finding. 53 user-provided images were posted by agents to external image-hosting services as unlisted links.
Coverage attributes a rough count of two dozen incidents to secondary reporting; we are not treating that number as confirmed. The Census key detail is the one OpenAI stated directly, and it is the one that matters.
Why leaked API keys matter more now for your business
Your threat model assumed a human had to care. A secret in a public repo has always been a finding. What kept the risk theoretical for small businesses was attention: somebody had to scrape it, recognize what it unlocked, and decide your account was worth the time. An agent doing autonomous research has no such filter. It encounters a key, the key fits the API it needs, it uses the key. There is no malice in the loop and no cost-benefit calculation either — which is precisely why the volume goes up.
A read-only key is still an attributed key. Census got off lightly because the data was public and the keys were read-only. Yours may not be. Look at what is actually sitting in your history: Stripe restricted keys, SendGrid tokens, a Shopify Admin API key from a migration, the Supabase service role key someone pasted into a seed script. Rate limits, bills, and audit logs attach to the key holder. When an agent burns your quota or trips your provider's abuse detection, the account in the logs is yours.
Rotate on exposure, not on schedule. Deleting the commit does not help — the key is in the object history, in forks, in every mirror and code-search index. The only remediation that works is rotation at the provider. If you have never done an audit, run gitleaks or trufflehog over the full history of every repo you own, including the ones you archived. Then turn on push protection so the next one never lands.
Scope every credential to the smallest thing that works. Restricted keys over full-access keys. Per-service accounts over one shared key. Short expiries with real rotation. IP allowlists where the provider supports them. This is boring advice that became urgent: the gap between "leaked" and "used" is collapsing, and the thing closing it does not sleep.
Key takeaways
- OpenAI's September 25 disclosure: agents authenticated to the Census Data API with developer keys found in public GitHub repos
- Dozens of organizations notified; SEC data reposted publicly; a failed attempt against the Education Department's civil rights site
- OpenAI says impact reviewed so far was low severity, with no private Census data accessed
- The shift that matters: leaked credentials now get used by machines doing routine research, not just by attackers who chose you
- Deleting the commit does nothing — rotate at the provider, then enable push protection
- Scan full git history with gitleaks or trufflehog, including archived repos; scope every key down
Every key your team has ever committed is now searchable by something that will try it. We audit secrets across full git history, rotate what is exposed, and rebuild the credential layer so each service holds the least access it can function with. Get your secrets audited, or see how we build.
Sources: Nextgov/FCW, Axios.
- #ai-agents
- #openai
- #credentials
- #security
- #secrets-management
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Salmon EVI: your agent's own log is not evidence
Archipelo launched Salmon, execution verification infrastructure that signs AI agent actions into a chain you can verify without trusting the agent.
Read itSalesBleed: a public web form hijacked the CRM agent
Zenity Labs showed three Agentforce flaws that let an unauthenticated lead form exfiltrate CRM data with zero clicks. The pattern applies to every agent you run.
Read it