Via getstealery.com
API keys from 659 Stripe merchants leaked, exposing 688K customer records
The breach didn't come from Stripe itself, but from merchants who left their secret keys lying around in public repos and misconfigured servers.
A hacker going by “Satanic” posted a trove of stolen data on PwnForums on August 18, claiming to have exfiltrated live API keys from roughly 659 merchants who use Stripe for payment processing. The haul: approximately 688,363 customer records spanning 42 countries, totaling somewhere between 33 and 35 gigabytes of sensitive payment and customer data.
The kicker is that Stripe’s own infrastructure wasn’t breached. The keys were harvested from the merchants themselves, pulled from public code repositories, infostealer malware, and misconfigured servers.
How 50,000 keys ended up in the open
The scale of the exposure goes well beyond the 659 merchants named in this particular dump. Investigations have found that over 50,000 Stripe API keys have been exposed in public domains, including GitHub Actions logs and web servers with broken access controls.
The majority of these were live-mode secret keys, the kind prefixed with sk_live. These aren’t sandbox credentials for testing. They’re the real thing, capable of initiating charges, issuing refunds, and accessing full customer payment details.
The threat actor also claimed to possess around 20,000 additional keys not included in this dump, suggesting this incident could be a preview rather than the full picture.
Merchants own the problem, and Stripe’s policies make that clear
Stripe’s terms of service place the responsibility for securing API keys squarely on the merchants who generate them. The company provides documentation, key rotation tools, and restricted key options specifically to help developers avoid this kind of disaster.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The pattern here is frustratingly familiar. Developers hardcode secret keys into application code, commit them to public GitHub repositories, or log them in CI/CD pipelines where they’re indexed by search engines. Infostealers, a category of malware designed to scrape credentials from infected machines, account for another chunk of the exposure. These tools harvest browser-stored passwords, session tokens, and yes, API keys from developer workstations.
What the exposed data contains
The 688,363 records reportedly include customer names, email addresses, partial payment details, and transaction histories. The exact composition varies by merchant, since each Stripe integration captures different fields depending on the business’s checkout flow.
The geographic spread across 42 countries also complicates the regulatory picture. Merchants operating in the EU face potential enforcement under GDPR, where data breaches involving payment information can trigger fines of up to 4% of annual global revenue.
The fintech security gap that won’t close itself
Secrets management, the practice of securely storing, rotating, and restricting access to credentials like API keys, remains one of the most neglected areas of application security. Tools like HashiCorp Vault, AWS Secrets Manager, and Stripe’s own restricted keys exist specifically to mitigate this risk.
The threat actor’s claim of holding 20,000 additional keys means this story likely has a second act. Merchants using Stripe would be wise to audit their key exposure immediately, rotate any potentially compromised credentials, and implement restricted keys with the narrowest possible permissions.