Rabbit
Disclosed Jun 26, 20242 years agoUnverified
Hardcoded API keys in Rabbit R1 code exposed users' AI assistant responses
The developer community rabbitude reported that hardcoded API keys in Rabbit's R1 backend, including ElevenLabs, Azure, Yelp and Google Maps keys, allowed retrieval of responses the R1 devices gave users, which could contain sensitive data. Rabbit said it rotated the keys.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jun 26, 2024 |
| Attack | Exposed data |
| Data exposed | Prompts and chats, API keys, Location |
| Sector | AI · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Rabbit R1 security issue leaves user requests accessible to others9to5google.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jun 26, 2024 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.