Security Affairs Reports Massive Leak of Stripe Merchant API Keys

Security Affairs Reports Massive Leak of Stripe Merchant API Keys

N
News Editor
2026-08-24 09:41:50
ChainCatcher, citing Security Affairs, reported that Ransomnews researchers documented a large-scale leak of Stripe merchant API keys. The exposed keys were found in public code repositories, GitHub Actions logs, and misconfigured web servers. Researchers identified more than 50,000 unique keys, and sample testing found that a substantial portion was still active. The report said attackers could use the keys to commit fraud within hours. According to the report, a data set posted on a data-trading forum on Aug. 18, 2026 contained valid Stripe API keys for 659 merchant accounts, along with about 35 GB of customer and payment data. Ransomnews analyzed the data offline and reported it to Stripe before publication. The report said Stripe itself was not breached and that the leaked keys belonged to merchants, not Stripe. Researchers said that once a valid key was found, it took as little as 17 hours to access customer lists, create fraudulent payment links, and run a $1 test charge. The report also said valid keys could be used to list customers and stored payment methods, create charges and payment intents, issue refunds to attacker-controlled accounts, change webhook endpoints to intercept payment notifications, and access connected accounts when Stripe Connect was enabled.
ChainCatcher, citing Security Affairs, reported a large-scale leak of Stripe merchant API keys. Ransomnews researchers said the exposed keys were found in public code repositories, GitHub Actions logs, and misconfigured web servers. The researchers identified more than 50,000 unique keys. Sample testing showed that a substantial portion was still active, and attackers could use them to commit fraud within hours. The report said that on Aug. 18, 2026, a data set posted on a data-trading forum included valid Stripe API keys for 659 merchant accounts, along with about 35 GB of customer and payment data. Ransomnews analyzed the data offline and reported it to Stripe before publication. The report said Stripe itself was not breached, and that the leaked keys belonged to merchants. Researchers said that after finding a valid key, they could access a merchant’s customer list, create fraudulent payment links, and complete a $1 test charge within 17 hours. According to the report, valid keys could also be used to list customers and stored payment methods, create charges and payment intents, send refunds to attacker-controlled accounts, modify webhook endpoints to intercept payment notifications, and access connected accounts when Stripe Connect was enabled. The main exposure sources included hardcoded keys and unignored .env files in GitHub repositories, unmasked environment variables in GitHub Actions build logs, and misconfigured servers. The report said roughly 12% of more than 3,000 misconfigured servers contained usable keys.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
10

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.