13:22
2026-06-18
dev.to
ai-agents
An API key in a React bundle: 33 days to compromise
An AI agent developer accidentally exposed a Brevo API key in a public React bundle for 33 days, leading to a compromise detected by Brevo's fraud system. The key was hardcoded in a TypeScript file anβ¦