A significant leak of over 50,000 Stripe API keys has been documented by researchers from Ransomnews. The keys were found in public code repositories and misconfigured servers, exposing merchant data and the ability for fraudsters to exploit them within hours. An analysis revealed that many keys were still active; one could be used to access customer lists, create fraudulent payment links, and even perform charges. Misconfigurations in GitHub repositories and server setups were common sources of this leak.
Stripe provides automatic scanning for keys but does not cover all scenarios, leading to recommendations for merchants to audit their keys and enable restricted access where appropriate.