A hacker going by “Satanic” posted a trove of stolen data on PwnForums on August 18, claiming to have exfiltrated live API keys from roughly 659 merchants who use Stripe for payment processing. The haul: approximately 688,363 customer records spanning 42 countries, totaling somewhere between 33 and 35 gigabytes of sensitive payment and customer data.

The kicker is that Stripe’s own infrastructure wasn’t breached. The keys were harvested from the merchants themselves, pulled from public code repositories, infostealer malware, and misconfigured servers.

How 50,000 keys ended up in the open

The scale of the exposure goes well beyond the 659 merchants named in this particular dump. Investigations have found that over 50,000 Stripe API keys have been exposed in public domains, including GitHub Actions logs and web servers with broken access controls.

The majority of these were live-mode secret keys, the kind prefixed with sk_live. These aren’t sandbox credentials for testing. They’re the real thing, capable of initiating charges, issuing refunds, and accessing full customer payment details.