Hardcoded API keys are showing up more often in the code behind healthcare AI research, and many of the leaks only exist in deleted commits, a new analysis finds.
Researchers at Asan Medical Center and the University of Ulsan in South Korea screened repositories linked to 5,322 healthcare LLM papers indexed since 2018. They confirmed exposed credentials in 22 papers, or 0.41%, mostly OpenAI-format keys at 50% and HuggingFace tokens at 32%.
The exposure rate climbed from 0.142% in papers published from 2018 to 2023 to 0.203% in 2024 and 0.698% in 2025, a 3.4-fold jump year over year. Digging through full commit histories uncovered more than twice as many exposed repositories as a simple snapshot, with 58% of those recoverable only from deleted commits.
The authors did not test whether the leaked keys still worked, so the practical risk to patient data remains theoretical for now. But as journals expand code-sharing mandates, the team argues publishing workflows need security safeguards such as automated secret scanning before papers go out.
The findings appear in Scientific Reports.
