OpenAI developer warns of automated searches for exposed keys and credentials by autonomous AI models
OpenAI developer roon warned on X that autonomous AI models will start searching en masse for exposed API keys, cryptocurrency wallet credentials, and login credentials on GitHub and Pastebin. He also recommended auditing smart contracts and shutting down old IoT devices because of the risk of botnets.
A developer at OpenAI going by the name “roon” (the @tszzl account on X) highlighted growing security risks associated with autonomous AI models. According to him, anyone with API keys, cryptocurrency wallet credentials, or user login credentials freely available on platforms such as GitHub or Pastebin should remove them before the “tireless eyes of a million models” find them.
roon also recommended that people with funds held in unsecured smart contracts have those contracts checked for vulnerabilities by a current AI model. According to him, “five-year-old” IoT devices should also be shut down because they risk becoming part of a botnet.
In a follow-up post, he softened his warning slightly, saying that he thought “everything will probably be fine,” but that it would still make sense for security experts to “panic and patch everything” in the coming weeks. According to roon, the warning was prompted by an autonomous hack of the Hugging Face platform linked to OpenAI, which he had described in an earlier post as a “warning shot.”
Why it matters
Exposed credentials in public repositories and tools have long been a known risk, but the warning highlights that autonomous AI models can automate and accelerate the search for and exploitation of these credentials at scale. For developers and companies, this means they need to check their own code, smart contracts, and older devices for exposed data before someone else does.
Two audiences, two different impacts
What this means
For individuals
Developers and individuals should check whether they have API keys, cryptocurrency wallet credentials, or login credentials freely available in public repositories or tools such as Pastebin, and either secure or shut down older IoT devices.
For a business
Companies should check whether they have exposed credentials in public code, unsecured smart contracts, or outdated IoT devices, because autonomous AI models can find and exploit such risks at scale.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.