Research · curated 30 Jun 2026
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
First reported thehackernews.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Leaked API keys and open AI proxies let attackers run model requests at the developer's expense and abuse the AI backend, exposing a widespread weakness across consumer AI apps.
Researchers tested 444 iOS AI chatbot apps and found 282 (nearly two-thirds) exposed paid AI access through network traffic, including plaintext API keys, reusable tokens, or backend proxy servers that accepted requests with no key at all. An attacker observing traffic could grab these credentials and issue model requests on the developer's account.