Your API key is probably already on GitHub

Search GitHub for OPENAI_API_KEY right now. The code search returns thousands of .env files, committed in plain text, sitting in public repos — keys for OpenAI, Anthropic, and every provider you can name. Some of them are still live.

This isn't a hacking story. Nobody broke in. The keys were pushed by the same people who paid for them — mostly by accident, mostly within the first week of a new project.

Search results, a leaked .env with redacted keys, and the fix commands

How it happens

It's almost never stupidity.

You start a project on a Friday night. The tutorial says "create a .env file and put your key in it." You do. It works. You commit. You push. The tutorial never mentioned the second step, because the tutorial author added .env to their own .gitignore five years ago and forgot it was ever a decision.

AI coding assistants made this worse — not because they leak keys, but because they removed the friction that used to slow you down. You scaffold a project in minutes now. The .env gets created, filled, and committed before you've ever thought about the repo's visibility settings. Speed is great. Speed also means the mistake ships before the thought does.

The consequences are faster than people assume

Bots watch GitHub's public event feed for exactly this pattern. A live key in a fresh commit is found in minutes, not days. What happens next depends on who's scanning: crypto mining on your quota, someone else's workloads on your dime, or just a burned key and a confusing bill. The provider doesn't care that it wasn't you — usage is usage.

GitHub's own secret scanning with push protection can block known key patterns at push time, and it's worth switching on. But it matches patterns it knows, from providers it covers. A slightly renamed variable, a less common provider, a self-hosted endpoint key — all of those sail straight through. Treat it as a seatbelt you don't control, not a lock.

The fix is boring, which is why it keeps getting skipped

1. .gitignore before the first commit, not after

.env goes in there on commit zero. Not when you "clean up later." Later is after the push, and after the push is too late — the key is in the history even if you delete the file.

2. Commit a .env.example, keep the real one local

Placeholders in the repo, secrets on the machine. Anyone cloning the project sees what variables exist without seeing the secrets themselves. Some tools go further and never want the key in a file at all — pi's config, for example, reads "$WALLABY_API_KEY" as an environment-variable reference, so the key itself never sits in the config. We published a two-minute walkthrough of that pattern; the same env-var discipline works for any tool that reads configuration files.

3. If it's a team, use an actual secret manager

Doppler, 1Password CLI, Vault — pick one. .env files over Slack is how "personal mistake" becomes "organizational incident."

4. Already committed? Deleting the file does nothing

The key lives in git history. Purge it with git filter-repo or BFG — GitHub's own guide to removing sensitive data walks through both — then rotate the key. Rotation is not optional. Assume every key that ever touched a public repo is compromised, because the scanners assume it too.

Purging .env from git history and rotating the key

5. Set spend limits and alerts on the provider side

A usage cap won't stop the leak, but it turns a disaster into an annoying email. Whatever providers you use, look for per-key limits and low-balance alerting — and prefer setups where one environment variable is the whole configuration surface, like the zero-config route, over ones that scatter keys across files.

None of this is new information

That's the point. The tooling got ten times faster and the hygiene stayed in 2015. Every vibe-coded project that skips step one is a donation to whoever's running the scraper.

The model isn't the dangerous part of your stack. The workflow is.


Disclosure: Wallaby Token sells prepaid API access to open-weight models — issuing API keys is our day job, so we have a commercial interest in key hygiene staying boring. On our side of the deal: every key you mint can carry its own spend cap, metering is per-token with itemized logs, and a leaked key with a cap is a nuisance, not a bankruptcy. Sign up comes with a $0.50 trial credit — enough to test whether our limits work the way this post says they should.