HALL OF
SHAME

[001] OpenAI API Key Exposed in Chrome Extension
date: 2026  |  severity: HIGH  |  status: DISCLOSED

Found a hardcoded OpenAI API key in the source of a published Chrome extension. The key was embedded in plaintext in a content script, visible to anyone who unpacked the extension. Reported to the developer.