65% of Leading AI Companies Found Leaking Secrets on GitHub
Wiz Security found 65% of top AI companies leaked secrets on GitHub, exposing sensitive data and highlighting critical security gaps.
AI companies may be racing to innovate, but many are leaving critical security gaps behind.
According to new research from Wiz Security, 65% of leading AI firms had verified secret leaks on GitHub, exposing sensitive data like API keys, tokens, and credentials often hidden in deleted forks and developer repositories.
These leaks risk revealing private models, organizational structures, and even training data — a growing concern for companies driving the generation of AI.
“Speed and security have to move together,” said the Wiz research team.
The study examined private firms from the Forbes AI 50, a benchmark list of leading AI innovators, including Anthropic, Glean, and Crusoe.
Wiz’s analysis showed that almost two-thirds of these companies had confirmed leaks.
For AI startups balancing growth with governance, the findings reveal a critical blind spot: secrets hidden “below the surface” in historical commits, forks, and developer gists that traditional scanners miss.
Wiz’s researchers used a three-dimensional framework for identifying the attack surface.
One alarming discovery involved an AI company whose deleted fork contained a Hugging Face token exposing access to more than 1,000 private models.
Another case uncovered LangChain API keys with high-level organizational permissions, and ElevenLabs was found leaking enterprise-tier API keys in plain text.
To counter the growing risk of secret leaks in AI development, organizations must adopt a proactive and layered defense strategy.
Security isn’t just plugging gaps — it’s building sustainable habits across code, people, and processes.
The Wiz research underscores a growing theme in AI security: innovation outpacing protection.
As companies race to train larger models and deploy them more quickly, the infrastructure supporting them is becoming a rich target for attackers.
Leaked credentials don’t just expose models — they open the door to supply chain compromise, model tampering, and data exfiltration.
Ultimately, AI progress cannot come at the cost of security.
This growing tension between innovation and protection highlights why adopting zero-trust principles — which assume no user, device, or connection is inherently safe — is becoming essential for securing the rapidly expanding AI ecosystem.
Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.
A critical BeeStation OS flaw lets attackers run remote code on unpatched Synology devices.
A new Zoom Workplace flaw (CVE-2025-64740) lets attackers escalate privileges on Windows.
Critical flaw in Monsta FTP (CVE-2025-34299) allows remote code execution without authentication, putting thousands of servers at risk.
Proofpoint uncovered UNK_SmudgedSerpent, an Iranian-linked espionage campaign that exploits trust and blurs attribution.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
