Why it exists¶
AI agents now work with real keys: API keys, OAuth tokens, GitHub tokens. They also read text from strangers all day: web pages, issues, packages and MCP tools. That text can steer them. Attackers know this. They now hunt the keys that agents and developer machines hold.
The numbers¶
CVEs published per year
- 2019: 17.3 thousand
- 2020: 18.3 thousand
- 2021: 20.1 thousand
- 2022: 25.1 thousand
- 2023: 28.8 thousand
- 2024: 40.0 thousand
- 2025: 48.2 thousand
Secrets leaked on public GitHub
- 2022: 10.0 million
- 2023: 12.8 million
- 2024: 23.8 million
- 2025: 29.0 million
- 29 million new secrets leaked on public GitHub in 2025, 34% more than in 2024, by the count of the 2026 report. This is the largest jump in one year that GitGuardian has recorded (GitGuardian, 2026).
- 1,275,105 of these leaked secrets were for AI services, 81% more than in 2024. Eight of the ten fastest-growing types of leaked secret were AI-related (GitGuardian, 2026).
- 24,008 secrets were in MCP configuration files on public GitHub. 2,117 of them were valid (GitGuardian, 2026).
- 64% of the secrets that leaked in 2022 were still valid in 2026. A revocation often does not occur (GitGuardian, 2026).
Recent incidents¶
| When | What happened |
|---|---|
| March 2025 | VMware ESXi. VMware fixed three zero-days that let an attacker escape a VM to the hypervisor. Attackers used them before the fix, and ransomware groups use them now (Security Affairs, The Register). |
| May 2025 | Pwn2Own Berlin. Researchers escaped VMware ESXi for the first time in the history of the contest, and also escaped VirtualBox and VMware Workstation (CSO Online). |
| August 2025 | s1ngularity. Malicious versions of the Nx package on npm ran on developer machines. The malware told the AI command-line tools on each machine (Claude, Gemini, Q) to search for secrets. 2,349 secrets leaked, most of them GitHub tokens (GitGuardian). |
| September and November 2025 | Shai-Hulud. A self-spreading npm worm stole npm and GitHub tokens from developer machines and used them to infect more packages. Its second wave, in November, exposed about 400,000 raw secrets in 30,000 GitHub repositories (BleepingComputer). |
| April 2026 | Claude Mythos Preview. Anthropic reported a model that finds zero-days and writes working exploits for every major OS and browser. It found a guest-to-host flaw in a production hypervisor. It is not public (Help Net Security). |
| September 2026 | A hijacked AI coding session. Mandiant reported an attacker who took over an active AI coding-assistant session at a software company. The session installed a poisoned package and an infostealer. The attacker stole GitHub OAuth tokens and spread Shai-Hulud to about 100 internal repositories. Mandiant recommends that raw API keys and long-lived OAuth tokens stay out of direct reach (The Hacker News). |
| September 2026 | Credential theft at machine speed. Google Threat Intelligence reported an autonomous, multi-agent attack framework. It took thousands of API and cloud credentials in less than six hours (The Hacker News). |
The pattern¶
- The machine of the agent holds real keys, in configuration files, environment variables and credential files.
- Something that the agent trusts runs code or gives instructions: a package, an issue, a tool.
- The keys go out in minutes, to an address that the attacker selects.
- The keys stay valid for a long time after the theft.
The answer¶
Pi Fortress removes step 1 and blocks step 3.
| Without Pi Fortress | With Pi Fortress |
|---|---|
| The key files of the agent hold real keys. A stealer takes keys that work. | The key files hold placeholders (pf_…). A placeholder works nowhere else. |
| A hijacked agent can send a key to any address. | The gateway puts in the real key only for the service that owns it. A placeholder sent anywhere else gets a refusal and an alert. |
| A key in a known format leaves in a header, a URL or a body. | The gateway strips live keys in known formats before they leave. |
| Malware on the agent can turn off a local guard. | The gateway is a separate box on the network cable. The agent cannot turn it off. |
| An agent can connect to any site. | With paranoid mode, the agent can connect only to the sites on your allowlist. |
The risk model, with each attack that we tested and its result, is published with the source. To start, refer to Getting started.
Sources¶
- CVEs per year: cve.icu and Jerry Gamblin, 2025 CVE data review.
- GitGuardian, The State of Secrets Sprawl 2026, as reported by The Hacker News, March 2026. Each bar uses the value of its own edition, and a later edition can revise an earlier count. The 2022 to 2024 values are from the 2024 and 2025 editions.
- GitGuardian, The Nx s1ngularity attack: inside the credential leak.
- BleepingComputer, Shai-Hulud 2.0 npm malware attack exposed up to 400,000 dev secrets.
- The Hacker News, Attacker hijacks AI coding assistant, September 2026.
- The Hacker News, Autonomous AI agents compromise thousands of credentials in under six hours, September 2026.