Can AI Tools Be Used to Steal API Keys?

Yes, and it’s already happening. Over the last few months, attackers have stolen API keys by breaking into self-hosted AI tools, by tricking AI systems into handing keys over, and by picking up keys that AI coding tools left behind in files and repos.

If your team has stood up an AI gateway, connected an AI agent to internal systems, or lets developers use AI coding assistants, this one is worth a few minutes. Those tools usually hold keys to OpenAI, Anthropic, Azure, Google and your own cloud accounts, which makes them a very attractive target.

Anthropic’s September 2026 threat report explains why attackers want these keys. A stolen AI key can be resold, it gives the attacker free compute on your bill, and it provides cover, because the activity traces back to you instead of them.

Way 1: Attackers break into the AI tools you host

AI gateways sit between your apps and the model providers, so they end up holding the keys for every provider they route to. LiteLLM is one of the most popular, and on September 2, CISA added its authentication bypass, CVE-2026-59822, to the Known Exploited Vulnerabilities catalog.

The flaw is in LiteLLM’s MCP endpoint, the part that lets AI agents call tools. Versions before 1.84.0 accept any made-up Bearer token as valid, so an attacker doesn’t need a password or a real key to get in.

Wiz ran honeypots on exposed AI infrastructure for 90 days and watched what attackers did once they were inside:

  • Pulled provider keys from the database — including upstream provider keys, provider endpoints and the virtual keys LiteLLM hands out

  • Read the master key out of memory — recovering the proxy’s master key straight from the running process

  • Stayed and mined — adding their own SSH keys for persistence and installing cryptocurrency miners

LiteLLM isn’t the only target. The same honeypots saw activity against Flowise, LangChain, Langflow, ChromaDB, Ollama, OpenWebUI, Marimo and Node-RED, and CISA’s same update included Kestra, a workflow tool attackers used to run their own jobs without logging in. Wiz also found that most of these tools ship without authentication turned on.

Way 2: Prompt injection talks the AI into handing keys over

This one doesn’t need a software bug. An AI model reads whatever content you give it, and if that content contains instructions, the model can end up following them. That’s called prompt injection, and it becomes a real problem once the AI holds credentials or can run commands.

Anthropic’s September 2026 threat report describes two cases:

  • An evaluation sandbox gave up its keys — a financially motivated group planted instructions in content an AI vendor’s automated test sandbox was processing, and the sandbox handed over the production API keys it held for several model providers

  • AI wrapper services leaked production keys — multiple attackers used prompt injection against services built on LiteLLM to pull the production API keys out of their cloud-hosted containers

Wiz saw a quieter version of the same idea. Attackers slipped instructions to AI agents that had shell access, telling them to look up an attacker-owned domain. Nothing showed up in the app, however the DNS request proved the injected instruction had reached a tool that could run commands.

The lesson for anyone building with AI agents is simple. If an agent reads untrusted content, like emails, tickets, web pages or uploaded files, anything that agent can reach is at risk, and that includes the keys in its environment.

Way 3: AI coding tools leave keys lying around

The third way is less dramatic, but it’s the one most teams already have. AI coding assistants make it easy to paste a key into a config file to get something working, and those keys end up in places nobody is scanning.

GitGuardian’s State of Secrets Sprawl 2026 report put numbers on it:

  • New secrets added to public GitHub in 2025 — 28.65 million, up 34%

  • Leaked AI service secrets — 1,275,105, up 81%

  • Leak rate in AI-assisted commits — 3.2%, vs. 1.5% for all public commits

  • Secrets found in public MCP config files — 24,008, of which 2,117 were valid

  • Valid secrets from 2022 still working in 2026 — 64%

In a follow-up published this week, GitGuardian pointed out that keys also spread outside the repo. They sit in AI agent and MCP config files, in local copies written for debugging, and in logs, prompts and shell history, all places your repo and CI scanners never look.

That last number above is the one that should worry you. A key that leaked years ago still works most of the time, because nobody rotated it.

What to do this week

None of this requires new tools to get started. Work through this list with your team or your clients.

  1. Find every AI tool running in your environment. Look for LiteLLM, Flowise, Langflow, Ollama, OpenWebUI and anything else someone stood up for a test, and treat each one as a production system.

  2. Patch LiteLLM to 1.84.0 or later. If you can’t patch today, block outside access to the /mcp/ paths at your reverse proxy, or turn off the MCP routes until you can.

  3. Take AI tools off the public internet. Put them behind a VPN or an authenticated proxy, and turn on authentication even for internal-only tools.

  4. Rotate provider keys on anything that was exposed or unpatched. Then check each provider’s usage dashboard for spending you can’t explain.

  5. Give each app its own key, with limits. Separate keys per app, spending caps at the provider, and cloud permissions scoped to only what the tool needs.

  6. Keep production keys away from agents that read untrusted content. If an agent processes emails, tickets or uploads, it shouldn’t be able to see your production keys, and shell or network tools should require an approval step.

  7. Scan beyond the repo. Check .env files, AI agent and MCP config files, and shell history on developer machines, and move what you find into a secrets manager.

  8. Watch for the signs. Unexpected outbound DNS lookups, new processes spawned by AI services, and changes to ~/.ssh/authorized_keys on AI hosts all showed up in these attacks.

The bottom line

AI tools can be used to steal API keys, and attackers are doing it right now. Treat your AI gateway as a credential store, treat anything an AI agent reads as untrusted, and rotate the keys your coding tools have scattered around.

If you’re running any of these tools and have questions about locking them down, let me know at opstacks@outlook.com.

Sources

CISA: CISA Adds Seven Known Exploited Vulnerabilities to Catalog (Sept. 2, 2026)Z

The Hacker News: CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

IONIX: CVE-2026-59822 – Authentication Bypass – LiteLLM prior to v1.84.0

Wiz: Attacks on AI Infrastructure, 90-Day Honeypot Telemetry

GBHackers: Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Anthropic: Countering misuse of AI, September 2026

GitGuardian: The State of Secrets Sprawl 2026

GitGuardian: AI Coding Agents Are Leaking Credentials on Endpoints

Next
Next

Multi-tenant KEV tracking without buying another platform