What a leaked Stripe key costs in the first hour

Nadia Brennan

Security research

6 min read

What a leaked Stripe key costs in the first hour

A live key in a public build log is found by scrapers in minutes. Here is what we saw, and what the fix looked like.

In August we planted three test keys in public CI logs, each scoped to a sandbox with no money in it, and watched. The first automated login attempt arrived 11 minutes after the log went public. By the end of the first hour, all three keys had been tried.

Why build logs

Most teams keep secrets out of their code. Fewer think about what their build prints. A debug line, a failing test that dumps its environment or a verbose deploy script is enough.

What the fix is

Rotating the key stops the damage, but it does not stop the next leak. The fix Quorum opens moves the value into your secrets manager, replaces the line with a reference and adds a check that fails the build if a live key pattern appears in output again.

The pull request is small on purpose: one line in the env file, one resource in Terraform, one step in CI. Two people can review it in the time it takes to read this post.

Run a free scan on one repo

Connect one repo and one cloud account with read-only access. You get the findings and the first fix pull requests within a day, and you keep them either way.

Use this free template

Create a free website with Framer, the website builder loved by startups, designers and agencies.