Research · curated 30 Jun 2026

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

Coverage timeline

30 Jun 2026thehackernews.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Leaked API keys and open AI proxies let attackers run model requests at the developer's expense and abuse the AI backend, exposing a widespread weakness across consumer AI apps.

Researchers tested 444 iOS AI chatbot apps and found 282 (nearly two-thirds) exposed paid AI access through network traffic, including plaintext API keys, reusable tokens, or backend proxy servers that accepted requests with no key at all. An attacker observing traffic could grab these credentials and issue model requests on the developer's account.