1,033 Live Stripe Secret Keys Leaked: How Exposed .env Files Became a Payment Rail Breach
1,033 Live Stripe Secret Keys Leaked: How Exposed .env Files Became a Payment Rail Breach On August 18, 2026, a threat actor dumped 1,033 live Stripe sk_live_... keys from 669 vendors on an illicit forum — with a direct claim to Hudson Rock that ~20,000 keys are held for staggered release. The leaked keys had charge capabilities, were tied to real invoices and promo-code tables, and the victims…
On August 18, 2026, a threat actor leaked the private keys of 1,033 Stripe accounts from 669 vendors on an underground forum. Hudson Rock, the security firm that discovered the leak, reported that the keys had full charge capabilities and were tied to real invoices and promo codes. The victims were using a variety of technology stacks, and there was no evidence of infostealer infections on the vendor domains.
The most likely cause of the leak was automated mass-scanning for publicly exposed .env files and debug logs, rather than a vulnerability in Stripe or a single WordPress plugin. The leaked keys included customer information, charges, balances, payouts, invoices, promo codes, and even URLs to valid Stripe invoices that exposed card last-four digits.
The breach was caused by misconfigured files that were found at scale, rather than a single vulnerable plugin. To prevent similar breaches in the future, developers should regularly check their systems for exposed .env files, rotate keys frequently, and minimize the scope of access granted to leaked keys.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.