Researchers Found Hardcoded Keys in Public MCP Files
A security analysis uncovered thousands of exposed credentials in AI configuration files, risking enterprise data.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you trust that businesses are successfully securing their AI tools against potential data breaches?
Security researchers analyzed 82,000 public Model Context Protocol (MCP) configuration files on GitHub and discovered that 12% of credential slots contained hardcoded secrets. These exposed files grant AI agents access to enterprise tools and sensitive token pools.
Why it matters
The widespread exposure of these credentials allows attackers to hijack AI agents and gain unauthorized access to sensitive corporate systems. This finding highlights the emerging risk of mismanaged authentication in AI integration workflows.
Analysis shows that 12% of credential slots in 82,000 analyzed MCP configuration files contain hardcoded secrets. Of those exposed credentials, 24% are confirmed to be non-expiring and broad-scope.
The players
Hush Security
A cybersecurity research firm focused on identifying vulnerabilities within modern software development and AI deployment workflows.
GitHub
The primary cloud-based platform where developers host code and configuration files, currently serving as the central repository for MCP files.
Anthropic
A major AI research and development company whose API keys were found among the exposed credentials.
OpenAI
A prominent artificial intelligence research organization whose API keys were identified in the breached configuration files.
The details
MCP configuration files function as instruction sets for AI agents, dictating which enterprise tools to access and the authentication methods required to connect. By embedding hardcoded API keys directly into these files, users inadvertently grant attackers the ability to exploit their AI agents by simply pasting the configuration into their own environment. The study identified that the exposed secrets specifically include API keys for services like Anthropic and OpenAI.
Timeline
September 23, 2026: Research findings regarding the credential leaks were published.
The Tech Race
This vulnerability highlights the systemic risks associated with the rise of insecure configuration management in AI agent ecosystems. It follows established patterns of accidental credential leaks previously documented in traditional public cloud repositories.
Developers and organizations using MCP configuration files should immediately audit their repositories to remove and rotate any hardcoded API keys. Systems using non-expiring credentials should be prioritized for re-authentication and the implementation of more secure secret management practices.
The takeaway
The exposure of credentials in MCP files underscores the necessity of treating AI configuration files with the same security rigor as application source code. Organizations should implement automated secret scanning for all configuration-as-code files to prevent similar leaks in the future.
Further reading
For broader trends in infrastructure security and data protection, explore our coverage in Cybersecurity.
Source note: This article includes information reported by TechTarget.
Live Poll
Do you trust that businesses are successfully securing their AI tools against potential data breaches?







