FeaturesPricingFAQSecurityAffiliatesContact

ProphetKey Security Research · 2026

API Key Exposure Report 2026

28.6M+ secrets leaked on public GitHub in 2025. AI-service key leaks up 81%. The year AI adoption changed software engineering — and made API key leaks worse.

Published September 15, 2026 · Compiled from public security research · 8 min read
28.6M+new secrets leaked on public GitHub in 2025+34% year-over-year, the largest single-year jump ever recorded
+81%surge in AI-service credential leaks (YoY)1,275,105 AI-service secrets exposed in 2025
2xClaude Code-assisted leak rate vs. baseline~3.2% of Claude Code commits leaked a secret vs. ~1.5% GitHub-wide
24,008unique secrets in MCP configuration filesGoogle API keys (19.2%), Perplexity.ai keys (11.2%), and more

The short answer

Because this question keeps coming up: yes, API keys leak at scale. GitGuardian detected 28.6M+ new secrets in public GitHub commits in 2025 — up 34% year-over-year — and AI-service credentials were the fastest-growing category, up 81%. The problem is not whether a key will leak; it is whether yours already has.

A note on method: This report compiles published, citable figures from GitGuardian's State of Secrets Sprawl 2025 and 2026 editions, Verizon's 2024 DBIR, and IBM's Cost of a Data Breach. ProphetKey did not generate the leak counts and does not disclose user data. Figures are reproduced for reference with their sources linked below.

Key findings

Secrets sprawl is accelerating faster than developers

Secrets have been growing about 1.6x faster than the active developer population since 2021. Public commits grew 43% in 2025, and leaked secrets grew with them — GitHub now hosts 4.6% repos containing at least one secret.

Source: GitGuardian State of Secrets Sprawl 2026

AI assistance doubled the leak rate

Claude Code-assisted commits leaked secrets at ~3.2%, roughly double the ~1.5% GitHub-wide baseline across 2025. More code being written faster means more tokens, keys, and service identities embedded without equivalent governance.

Source: GitGuardian State of Secrets Sprawl 2026

AI service keys are the fastest-growing leak category

Leaks tied to AI services rose 81% year-over-year to 1,275,105 secrets. AI-service credentials are more likely to slip past protections built for conventional developer workflows because they lack standardized prefixes.

Source: GitGuardian State of Secrets Sprawl 2026

The new leak vector: MCP and agent config files

As MCP became the standard way to connect LLMs to external APIs, researchers found 24,008 unique secrets exposed in MCP configuration files. Top types: Google API keys (19.2%), PostgreSQL connection strings (14%), Firecrawl keys (11.9%), Perplexity.ai API keys (11.2%), and Brave Search keys (11%).

Source: GitGuardian State of Secrets Sprawl 2026

Leaked keys stay usable for years

70% of secrets leaked in 2022 were still valid in 2024. By 2026, 64% of those valid secrets still had not been revoked. A single unrevoked key is an open door.

Source: GitGuardian State of Secrets Sprawl 2025 & 2026

Secrets managers do not stop sprawl

A study of 2,584 repositories using secrets managers found a 5.1% leakage rate — higher than the 4.6% public GitHub average. Secrets get copied out of managers and hardcoded elsewhere.

Source: GitGuardian State of Secrets Sprawl 2025

Where secrets leak

Secrets sprawl extends well beyond code repositories. Roughly 28% of incidents originate from collaboration and productivity tools — Slack (2.4% of analyzed channels contained leaked secrets), Jira (6.1% of tickets), and container registries (7,000+ valid AWS keys exposed on Docker Hub).

Leak vectorMeasured exposure
Public GitHub commits (2025)28.6M+ new secrets · +34% YoY
AI-service credentials (2025)1.28M+ · +81% YoY
MCP configuration files (2025)24,008 unique secrets
Claude Code-assisted commits (2025)~3.2% leak rate vs. ~1.5% baseline
Public repos with ≥1 secret (2024)4.6%
Repos with secrets managers that still leaked (2024)5.1%
Valid 2022 secrets never revoked (2026)64%

How to actually protect your keys

  1. Encrypt keys locally, never in config files. Plaintext keys in .env, MCP configs, or agent setup files are exactly what automation scans for.
  2. Use per-tool virtual keys. When one leaks, rotate the virtual key — your real provider key stays untouched.
  3. Treat any exposed key as compromised. Since 64% of valid leaked secrets are never revoked, assume attackers have already copied it.
  4. Monitor for your own keys. Public-repo scanning catches accidental commits the moment they ship.
ProphetKey: a local-first vault that encrypts API keys on-device (XChaCha20-Poly1305 + Argon2id), injects them into tools through a local proxy with shadow keys per tool, and includes leak monitoring so exposed keys are flagged fast. → Download for Windows

Sources

FAQ

How many API keys leak every year?

28.6M+ new secrets were detected in public GitHub commits in 2025 (GitGuardian State of Secrets Sprawl 2026), a 34% increase over 2024. In 2024 the figure was 23.8M.

Are AI-generated or AI-assisted projects more likely to leak API keys?

Yes. Claude Code-assisted commits leaked secrets at ~3.2% in 2025, roughly double the ~1.5% GitHub-wide baseline. AI-service key leaks specifically surged 81% year-over-year.

Do API keys leak through MCP or AI agent configuration files?

Yes. GitGuardian found 24,008 unique secrets exposed in MCP configuration files in 2025, including Google API keys (19.2%), Firecrawl keys (11.9%), and Perplexity.ai API keys (11.2%).

How long do leaked API keys stay usable?

70% of secrets leaked in 2022 were still valid in 2024, and 64% of valid secrets from 2022 were still not revoked by 2026 (GitGuardian). Leaked keys routinely remain active for years.

Do secrets managers prevent API key leaks?

No. Repositories using secrets managers leaked at 5.1% in 2024 — higher than the 4.6% GitHub-wide average (GitGuardian), because secrets are extracted from managers and hardcoded elsewhere.

How can developers protect their API keys?

Store keys in a vault encrypted locally (XChaCha20-Poly1305 + Argon2id), never paste them into config or MCP files, use per-tool virtual keys so a leaked key can be rotated without reissuing the real one, and monitor public code for your own keys.

This report is informational. Figures are from third-party research cited above and may be updated as new editions are published. Product description: prophetkey.com.