Severity

high

Exposure

4/5

Date of incident

March 20, 2023
OpenAI Redis exposed API keys

confirmed

Tier -

A

Provider bug exposed API keys — agents with embedded keys lacked ingress vault boundary.
What Happened

Cache misconfiguration exposed chat session metadata and active API keys to unauthorized users for a short window; teams with agents embedding keys in IDE and MCP configs faced rotation and blast-radius review.

Sumarry

OpenAI disclosed a Redis cache bug that briefly exposed active API keys and limited user data — relevant to any agent stack using OpenAI APIs.

Detect

Key rotation + NHIM-014 on env patterns

What Happened

Trust Vault in-cluster hydrate — never raw keys in agent context

Blekline //

In-cluster Trust Vault — keys never in model context

Without agent boundary //

Rotate keys after vendor disclosure — no prevent at ingress

Financial services AI security use case

Looking to integrate AI company-wide?