A few years ago, Security Magazine reported on a study that found up to 24 billion username and password combinations circulating on the dark web in 2022. This doesn’t even begin to account for all the exposed tokens, secrets, and API keys sitting in public repositories across GitHub or Hugging Face. All of this information is accessible to anyone with an internet connection—but thanks to the processing power of agentic AI, they can now be discovered and executed at record speed.
Info stealers who specialize in this kind of breaching regularly use AI-powered tools to scrape publicly exposed user credentials. Now—as we have just seen with OpenAI—apparently large language models can even find and use these exposed logins of their own volition. So how does one protect their user accounts on online platforms? First, you have to see if your credentials have been exposed. Then you have to take immediate steps to remediate them.
Why the OpenAI agent went rogue
OpenAI public disclosure on Hugging Face security breach Credit: OpenAIBut this agent found a zero-day vulnerability in a package registry tool called Artifactory, then used it to gain access to the web. From there, the OpenAI agent gained access to Hugging Face’s company systems using publicly exposed credentials across four separate services. It went on to spend two days inside the company’s internal systems, managed to secure root access to several production servers, and even enrolled 181 attacker-controlled devices into Hugging Face’s corporate network.
As for how the AI agent was able to get past the model’s usual safeguards, OpenAI noted that due to the nature of the ExploitGym evaluation, the agent was operating on instructions that reduced cyber refusals to successfully evaluate the model. OpenAI’s disclosure notes that this issue isn’t limited to Hugging Face: It’s since found instances where its agents found and used leaked credentials across different platforms. Now the AI company is collaborating with Hugging Face to uncover more details about the attack and prevent further instances like this one.
Anthropic issues public notice on three separate security incidents Credit: AnthropicBut in this case, Anthropic claims that the test environments each had a configuration error that left the Claude models with internet access, which was not part of the evaluation protocol. It seems they didn’t even need to uncover or target an exploit in the evaluation environment because the misconfiguration was already there.
Where do AI models find exposed credentials?
Researchers uncover more than 1,500 exposed API keys on Hugging Face Credit: Lasso SecurityRight after a major data breach or cyber attack, dump files containing huge numbers of compromised usernames, passwords, emails, and other sensitive data end up on dark web forums and marketplaces. They are searchable and often openly accessible, which means agents can find them just as easily as a human attacker can.
Exposed credentials in source code
Developers often commit API keys, tokens, and passwords to public coding repositories by mistake, especially when they’re in a rush or using vibe coding tools for assistance. If a human being were to scroll GitHub or Hugging Face, they wouldn’t see these credentials out in the open. But if any hacker or AI agent decides to peek underneath for the source code, those credentials are easily reachable. In 2023, Lasso Security uncovered more than 1,500 exposed API keys on Hugging Face, many of which belonged to major tech companies like Meta and Google.
Targeted prompt injection attacks
Even if your credentials aren’t exposed in advance, prompt injection has made it incredibly easy to break into someone’s device and scrape for any user credentials and logged-in accounts within reach. Hackers can manipulate AI agents with access to your local storage to search for unprotected passwords and browser session cookies, which can then be fed remotely to attackers who can use them to breach your private accounts. If your AI agent has access to your local device and web browser, you’re especially vulnerable. In some cases, a remote hacker may fully take over your system and quietly run surveillance without you even realizing.
How to check your current exposure
Have I Been Pwned lets you scan your email and passwords against known data leaks Credit: Have I Been PwnedHave I Been Pwned maintains a continuously updated library of known info steals and data breaches. They pulled 56 million email addresses from stealer logs in a single batch in June 2026 alone. It’s also entirely searchable and free to use.
Scan your code repositories for exposed secrets
If you write code, own a website, or maintain any public repositories, there’s a good chance that private credentials like passwords or tokens may end up in your public-facing source code files due to human error or technical issues.
If you own a WordPress site with lots of plugins or themes, you can find similar vulnerabilities using WPScan. GitHub repositories also have access to their own built-in secret scanning tool, which can scan your repos for compromised API keys in a few clicks.
Review your AI agents for permissions and connected apps
Another thing you should do is review your AI platform’s activity logs to make sure it’s not doing anything that you haven’t authorized, like accessing folders on its own or exchanging data with sources you haven’t approved. If you see anything suspicious, revoke permissions immediately to avoid further damage and change your compromised account credentials.
What to do if you’ve been exposed to AI scraping
You should decommission your old accounts when you stop using them Credit: LinkedInIf you suspect a password has been compromised, either through public data leaks or prompt injection attacks targeting your device, the first course of action is to log into your account and reset that password. You can use a random password generator to create one that’s hard to guess, ideally with a mix of numbers and symbols along with text.
Rotate your API keys and tokens the moment a leak is suspected
If your compromised data includes any API keys, tokens, secrets, or other developer credentials in publicly accessible source code, don’t wait until a cyber attack occurs to reset them. It’s best to assume that an attack is likely if it’s not already taken place, so replace your credentials with new ones at once.
Two-factor authentication (2FA) is a fundamental security stopgap that prevents most account takeover attempts during cyber attacks. Even if a hacker manages to secure a compromised password, they can’t actually get into your accounts unless they also have access to the one-time code from your authenticator app or your private security key.
Authenticator apps like Google Authenticator, Bitwarden, 2FAS, Authy, etc. offer much better security because they’re locked to your specific device and account. Physical security keys are also a great option that insulates you from all forms of digital attacks altogether since logging in requires access to a piece of physical hardware.
Don’t hardcode your credentials into a repository
AI agents or browsers like ChatGPT Work, Perplexity Comet, Dia, or Claude Cowork live directly on your desktop and execute tasks like coding, file management, and web browsing autonomously. But if you give them blanket access to your whole device, prompt injection attacks can easily steal files that store your credentials or active cookie sessions from logged-in accounts in your browser.
Decommission old accounts when you stop using them
When you stop using online accounts but don’t actively delete or decommission them, they continue to sit in a company database along with your old password, payment details, and other personal information. These dormant accounts on online platforms are a favorite target for AI-augmented info stealers, who find them easier to exploit due to reduced security measures and outdated authentication.
Some companies will still keep your data on file for compliance reasons for a set period after decommissioning the account, but that’s usually not an indefinite amount of time, and your account won’t be sitting open to exploitation in the meantime.
Hence then, the article about ai bots can steal your login credentials but you can protect yourself was published today ( ) and is available on Live Hacker ( Middle East ) The editorial team at PressBee has edited and verified it, and it may have been modified, fully republished, or quoted. You can read and follow the updates of this news or article from its original source.
Read More Details
Finally We wish PressBee provided you with enough information of ( AI Bots Can Steal Your Login Credentials, but You Can Protect Yourself )
Also on site :
- Kevin Warsh’s first big press conference shines a spotlight on confusion over how the Fed actually measures inflation
- Ractigen Therapeutics Announces U.S. FDA IND Clearance for First-in-Class saRNA Candidate RAG-1C to Treat Proliferative Vitreoretinopathy
- 'Vulgar, Heartwarming' Trailer for Olivia Colman and Alexander Skarsgård’s New Film Leaves Fans Stunned