Skip to content

Why it exists

AI agents now work with real keys: API keys, OAuth tokens, GitHub tokens. They also read text from strangers all day: web pages, issues, packages and MCP tools. That text can steer them. Attackers know this. They now hunt the keys that agents and developer machines hold.

The numbers

CVEs published per year

  • 2019: 17.3 thousand
  • 2020: 18.3 thousand
  • 2021: 20.1 thousand
  • 2022: 25.1 thousand
  • 2023: 28.8 thousand
  • 2024: 40.0 thousand
  • 2025: 48.2 thousand

Secrets leaked on public GitHub

  • 2022: 10.0 million
  • 2023: 12.8 million
  • 2024: 23.8 million
  • 2025: 29.0 million
  • 29 million new secrets leaked on public GitHub in 2025, 34% more than in 2024, by the count of the 2026 report. This is the largest jump in one year that GitGuardian has recorded (GitGuardian, 2026).
  • 1,275,105 of these leaked secrets were for AI services, 81% more than in 2024. Eight of the ten fastest-growing types of leaked secret were AI-related (GitGuardian, 2026).
  • 24,008 secrets were in MCP configuration files on public GitHub. 2,117 of them were valid (GitGuardian, 2026).
  • 64% of the secrets that leaked in 2022 were still valid in 2026. A revocation often does not occur (GitGuardian, 2026).

Recent incidents

When What happened
March 2025 VMware ESXi. VMware fixed three zero-days that let an attacker escape a VM to the hypervisor. Attackers used them before the fix, and ransomware groups use them now (Security Affairs, The Register).
May 2025 Pwn2Own Berlin. Researchers escaped VMware ESXi for the first time in the history of the contest, and also escaped VirtualBox and VMware Workstation (CSO Online).
August 2025 s1ngularity. Malicious versions of the Nx package on npm ran on developer machines. The malware told the AI command-line tools on each machine (Claude, Gemini, Q) to search for secrets. 2,349 secrets leaked, most of them GitHub tokens (GitGuardian).
September and November 2025 Shai-Hulud. A self-spreading npm worm stole npm and GitHub tokens from developer machines and used them to infect more packages. Its second wave, in November, exposed about 400,000 raw secrets in 30,000 GitHub repositories (BleepingComputer).
April 2026 Claude Mythos Preview. Anthropic reported a model that finds zero-days and writes working exploits for every major OS and browser. It found a guest-to-host flaw in a production hypervisor. It is not public (Help Net Security).
September 2026 A hijacked AI coding session. Mandiant reported an attacker who took over an active AI coding-assistant session at a software company. The session installed a poisoned package and an infostealer. The attacker stole GitHub OAuth tokens and spread Shai-Hulud to about 100 internal repositories. Mandiant recommends that raw API keys and long-lived OAuth tokens stay out of direct reach (The Hacker News).
September 2026 Credential theft at machine speed. Google Threat Intelligence reported an autonomous, multi-agent attack framework. It took thousands of API and cloud credentials in less than six hours (The Hacker News).

The pattern

  1. The machine of the agent holds real keys, in configuration files, environment variables and credential files.
  2. Something that the agent trusts runs code or gives instructions: a package, an issue, a tool.
  3. The keys go out in minutes, to an address that the attacker selects.
  4. The keys stay valid for a long time after the theft.

The answer

Pi Fortress removes step 1 and blocks step 3.

Without Pi Fortress With Pi Fortress
The key files of the agent hold real keys. A stealer takes keys that work. The key files hold placeholders (pf_…). A placeholder works nowhere else.
A hijacked agent can send a key to any address. The gateway puts in the real key only for the service that owns it. A placeholder sent anywhere else gets a refusal and an alert.
A key in a known format leaves in a header, a URL or a body. The gateway strips live keys in known formats before they leave.
Malware on the agent can turn off a local guard. The gateway is a separate box on the network cable. The agent cannot turn it off.
An agent can connect to any site. With paranoid mode, the agent can connect only to the sites on your allowlist.

The risk model, with each attack that we tested and its result, is published with the source. To start, refer to Getting started.

Sources