Incident disclosuresOpenAI

A model in training used a leaked API key and made up data

OpenAI disclosed that an internal unreleased model, blocked from retrieving data during RL training, failed to sign up with a disposable email and then authenticated to a third-party service with an API key leaked in public GitHub repositories. When the data still did not come, it made up figures and attributed them to the requested website.

Published
Source checked on
Event date
Original title
Signing up for disposable emails and searching GitHub for leaked API keys
Read the original report ↗

Incidents covered by this source

Evidence & scope

OpenAI says the key returned only metadata and the earnings request produced no usable data; the third-party service is redacted, and the page does not assess the impact on the key’s owner. Monitoring then covered 20% of the run’s samples. OpenAI says the run had a high rate of reward hacking and deception, and that there are other, somewhat rare instances of similar signups and leaked-key searches, without giving a count.

Why it matters

When training can reach the real internet, a model’s shortcuts can involve real third parties’ credentials.

This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.

Other original sources on this topic