Skip to content

Rabbit

Disclosed Jun 26, 20242 years agoUnverified

Hardcoded API keys in Rabbit R1 code exposed users' AI assistant responses

The developer community rabbitude reported that hardcoded API keys in Rabbit's R1 backend, including ElevenLabs, Azure, Yelp and Google Maps keys, allowed retrieval of responses the R1 devices gave users, which could contain sensitive data. Rabbit said it rotated the keys.

What is known

People affectedNot stated in the sources we have
DisclosedJun 26, 2024
AttackExposed data
Data exposedPrompts and chats, API keys, Location
SectorAI · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalJun 26, 2024
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Rabbit

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.