Site navigation

65% of Private AI Companies Exposed Secrets on GitHub, Report Claims

Graham Turner

,

AI security leaks
The findings highlight a growing security gap among high-profile firms, including several on the Forbes AI 50 list.

A new study has revealed that nearly two-thirds of the world’s leading private artificial intelligence companies have leaked sensitive information on GitHub, underscoring growing concerns about security practices in the rapidly evolving AI sector.

According to the Exposure Report published by Wiz, researchers found that 65% of companies included in the Forbes AI 50 list had verified secret leaks – including exposed API keys, tokens and credentials – hidden deep within deleted forks, gists and developer repositories rarely examined by traditional scanners.

Some of these leaks could have exposed organisational structures, training data or even private AI models.

The study forms part of Wiz’s ongoing series examining AI-driven secret leaks, and its findings build on earlier work that assumed any company with a large enough GitHub footprint was likely to have exposed secrets.

This time, the researchers focused specifically on high-profile AI startups, operating under the hypothesis that any AI company of sufficient scale “definitely” has secrets exposed somewhere in its development ecosystem.

Deep Scan Reveals $400 Billion in Exposed AI Assets

The Forbes AI 50 list – considered one of the most recognised benchmarks for innovation in artificial intelligence – features companies shaping the next generation of the field, from major players like Anthropic to emerging firms such as Glean and Crusoe. Wiz said this made it an ideal sample for assessing how well security practices are keeping pace with rapid technological growth.

To conduct the research, Wiz developed a deep scanning methodology designed to go beyond surface-level analysis. The firm rejected traditional scanning of GitHub organisations as “commoditised”, instead focusing on three key dimensions: Depth, Perimeter and Coverage.

Depth involved searching full commit histories, deleted forks, workflow logs and gists to uncover data “below the surface.” The Perimeter scan expanded to identify organisation members and contributors who may have inadvertently uploaded company-related secrets to their personal repositories.

To identify these individuals, Wiz examined public organisation memberships, follower networks, account metadata, and correlated activity across related developer platforms such as HuggingFace and npm.

In total, the companies identified with verified secret leaks were collectively valued at over $400 billion.

The smallest company found to have exposed data had no public repositories and just 14 organisation members, highlighting that even firms with limited public activity can face risk. In contrast, the company with the largest GitHub footprint that did not leak any secrets maintained 60 public repositories and 28 members, suggesting that a robust secrets management strategy can prevent exposure regardless of scale.

Wiz noted that the types of secrets leaked by AI companies mirrored those seen in its earlier research, with credentials linked to platforms such as Weights & Biases, ElevenLabs and HuggingFace among the most common.

While leaks in major firms such as ElevenLabs and LangChain were promptly disclosed and fixed, Wiz said the overall disclosure landscape remains problematic. “Almost half of disclosures either failed to reach the target or received no response,” the report stated, noting that many companies lacked official disclosure channels or failed to reply to security notifications.

Nevertheless, several organisations acted quickly to address their vulnerabilities. In one example, LangChain was found to have multiple Langsmith API keys exposed in code and configuration files, including enterprise-tier credentials with permissions that could allow attackers to list organisational members.

ElevenLabs, meanwhile, was found with an enterprise API key stored in plaintext, a case the researchers said illustrated the link between “vibe coding” and secrets leakage. Another unnamed company was found with a HuggingFace token in a deleted fork that granted access to roughly 1,000 private models, as well as several Weights & Biases keys leaking training data for private models.

The researchers stressed that while not every AI50 company was found to have a leak, the findings carried important lessons for the wider industry. Wiz recommended that all firms using public version control systems should immediately deploy secret scanning tools, and that startups in particular should establish clear disclosure channels from inception.


Recommended reading


Real-time monitoring and traceability “Disclosure channels are an essential element of a security programme, and for AI innovators they’re especially necessary from inception,” the report stated. It also advised AI service providers to develop detection systems tailored to their own secret types, arguing that too many companies “leak their own API keys while ‘eating their dogfood.’”

Beyond technical measures, Wiz called on companies to treat employees and contributors as part of their attack surface. It advised creating version control policies covering developer accounts, the use of multi-factor authentication, and segregation of personal and professional activity. The researchers also urged organisations to update their scanning tools regularly as new AI platforms and file types introduce fresh vectors for exposure.

“While modern secret scanning has elevated the ‘defence waterline,’ our investigation clearly shows that threats lurk deep below the surface – in deleted forks, gists, and developer repos,” the report concluded. “For AI innovators, the message is clear: speed cannot compromise security.”

Wiz’s final recommendation was for the AI industry to adopt a “Depth, Perimeter, and Coverage” mindset to raise defence standards and secure the next generation of artificial intelligence development.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data