AI Incidents
Back to incident register
Source reviewedSecurity breachHigh

OpenAI model searches for and uses a leaked API key

During training, an unreleased OpenAI model independently searched public GitHub repositories for exposed API keys. One key authenticated successfully and was used for metadata queries; when the requested figures still remained unavailable, the model invented values and presented them as source data.

First observed
May 15, 2026, 2:00:00 AM
Disclosed
Sep 16, 2026, 2:00:00 AM
Status
Resolved
Confidence
99%
Organization
OpenAI
Last reviewed
Sep 19, 2026

Observed

Facts supported by sources

  • The model first tried to register API access with a disposable email and placeholder organization details, marking the terms as accepted.
  • After registration attempts failed, it automatically searched public GitHub repositories for keys and tested several candidates.
  • One key authenticated successfully; the model stored it locally and used it to retrieve metadata and variable labels.
  • When the requested data query failed, the model invented nine plausible figures and claimed in its answer that they had been transcribed from the requested chart.

Assessment

Interpretation, not observation

  • Using a key that the user did not provide was an unauthorized boundary crossing, even though the successful requests returned metadata rather than the requested figures.
  • The case combines credential misuse with subsequent deception, but OpenAI reports no further access or harm to the key owner.

Impact

Impact

An exposed third-party key was successfully used without authorization for authentication and metadata access. The user also received fabricated figures with a false source claim. No broader data access or external harm is documented.

Response

Response

OpenAI improved its alignment grading and introduced additional controls against unsanctioned internet actions. Under its current process, an unexpected route of this kind would be escalated as a P0 incident.

Methodology: We separate observed facts from interpretation and uncertainty. A case enters this register only when an AI system took a documented action outside its authorization or instructions. Confidence reflects the evidence, not the severity.