Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Rabbit R1 Hard-Coded API Keys 2024: How Leaked…
Breach analysis Incident: 25 Jun 2024

Rabbit R1 Hard-Coded API Keys 2024: How Leaked Source Code Exposed the AI Device’s ElevenLabs, Azure, Yelp and Google Maps Keys

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
Attack route: Insider Leaked secret Identities: API key
On this page

On 25 June 2024, Rabbitude, a community that reverse engineers the Rabbit R1 AI gadget, published claims that Rabbit Inc.'s source code contained hard-coded API keys for the third-party services behind the device. Rabbitude said it had obtained access to the codebase on 16 May 2024 and found working keys for ElevenLabs (text-to-speech), Microsoft Azure (speech), Yelp and Google Maps. It claimed the ElevenLabs key alone could be used to read past R1 responses, change voices and disrupt every device, and that Rabbit had known about the keys and not acted. Rabbit rotated its keys from 25 June, causing brief downtime. On 5 July Rabbit said an employee had leaked a copy of internal code to the group, and that its logs showed the only abuse of the keys was sending defamatory emails to staff, a few journalists and group members through its email service. It said no customer data was exposed. The case shows how keys embedded in code travel with every copy of that code.

Key takeaways

  • Rabbit's source code contained hard-coded API keys for ElevenLabs, Azure, Yelp and Google Maps, and a fifth key for an email service, according to Rabbitude and TechRadar.
  • Rabbit says an employee leaked a copy of its internal code to the group. The employee was terminated and is under investigation, according to Rabbit's 5 July 2024 update.
  • Rabbitude claimed the ElevenLabs key could read past text-to-speech messages and could be used to break every R1. Rabbit said the key did reach bulk pseudo-anonymised data and could cause a temporary voice outage, but would not "brick" devices.
  • Rabbit confirmed one real misuse: the leaked email key was used to send defamatory emails to employees, a few journalists and group members. It said "no customer data was exposed in this event."
  • The identity lesson: an API key in source code is shared with everyone who ever gets a copy of that code, including insiders, so keys belong in a secrets manager and need an owner who can rotate them quickly.

At a glance

OrganisationRabbit Inc. (maker of the Rabbit R1 AI device)
WhenCodebase obtained 16 May 2024, according to Rabbitude; disclosed by Rabbitude 25 June 2024; Rabbit updates 26 June, 27 June and 5 July 2024
AttackerRabbitude, a reverse engineering community Rabbit calls a hacktivist group, which obtained the code from a Rabbit employee, according to Rabbit
Entry pointA copy of Rabbit's internal source code leaked by an employee, with API keys hard-coded in it
Identities abusedAPI keys for ElevenLabs, Azure, Yelp, Google Maps and an email service (SendGrid, named by Rabbit) embedded in the code
ImpactKeys rotated with brief device downtime; the email key was used to send defamatory emails; Rabbit says no customer data was exposed
CategoryNHI, LLM and AI platform. Incident class: confirmed NHI breach (hard-coded API keys obtained through an insider leak and used to send emails)

What happened

The Rabbit R1 is a small handheld AI device that launched in April 2024 at $200, according to 9to5Google. Users speak requests, which go to Rabbit's cloud service, which then calls third-party services to answer them, such as ElevenLabs to turn text into speech. Rabbitude, a group of developers taking the device apart, said in its disclosure that it gained access to Rabbit's codebase on 16 May 2024. There it found what TechRadar quotes it as calling "several critical hardcoded API keys": for ElevenLabs, Azure, Yelp and Google Maps.

Rabbitude said the ElevenLabs key had full privileges. It claimed the key could be used to read a history of past text-to-speech messages, which would reveal R1 responses, to change or delete voices, and potentially to make every R1 stop working. The group wrote that "we have internal confirmation that the rabbit team is aware of this leaking of api keys and have chosen to ignore it," and that "the api keys continue to be valid as of writing." TechRadar reported that Rabbitude deliberately withheld details of a fifth key, which it said gave access to emails sent from the r1.rabbit.tech subdomain used by the device's spreadsheet feature, and which "also allows us to send emails from rabbit.tech email addresses".

Rabbit's first response, given to Engadget and quoted by TechRadar and 9to5Google, was: "As of right now, we are not aware of any customer data being leaked or any compromise to our systems." Its own security page said that on 25 June it learned a third party might hold working API keys, and that it rotated them, causing brief device downtime. TechRadar reported that one key was revoked improperly, causing a temporary text-to-speech outage. On 27 June Rabbit said some secrets had not been stored properly in AWS Secrets Manager and that it was revoking and rotating all secrets and adding automated checks to stop secrets being committed to code.

On 5 July Rabbit gave its findings. It said it had evidence that an employee leaked a copy of confidential internal code to the group, and that the employee had been terminated. Its logs showed the only abuse was the sending of defamatory emails to employees, a few journalists and members of the group. The ElevenLabs key had access to bulk pseudo-anonymised data and could change global voice settings, but Rabbit said it would not brick devices. The SendGrid key could only send to @r1.rabbit.tech addresses and could not read historical email. Rabbit said "no customer data was exposed in this event", cut its vulnerability disclosure timeline from 180 to 90 days and commissioned a third-party audit of its code.

Timeline

DateEvent
April 2024The Rabbit R1 launches.
16 May 2024Rabbitude gains access to Rabbit's codebase, according to the group.
25 June 2024Rabbitude publishes its disclosure; Rabbit learns a third party may hold working keys and starts rotating them.
26 June 2024Rabbit posts its first security update; 9to5Google reports the issue.
27 June 2024Rabbit says some secrets were not stored in AWS Secrets Manager and begins revoking all secrets; TechRadar reports the findings.
5 July 2024Rabbit says an employee leaked the code, the email key was used for defamatory emails and no customer data was exposed.

How it happened: the identity attack path

  1. Keys embedded in code. API keys for third-party services were hard-coded into Rabbit's source code instead of being held in a secrets manager, which Rabbit acknowledged for some secrets.
  2. Code leaves the company. According to Rabbit, an employee leaked a copy of the internal code to the hacktivist group, and with it every key the code contained.
  3. Keys stay valid. Rabbitude says it had the code from mid-May and that the keys still worked when it published on 25 June.
  4. Keys used. Rabbit's logs showed the email service key was used to send defamatory emails from Rabbit addresses.
  5. Forced rotation. Rabbit rotated all known secrets after the disclosure, causing downtime, and moved them into AWS Secrets Manager.

Impact

  • Confirmed by Rabbit: working API keys were exposed through leaked code; the email key was misused to send defamatory emails; keys were rotated with brief device downtime.
  • Disputed: Rabbitude claimed the ElevenLabs key exposed every R1 response and could brick all devices. Rabbit said it reached bulk pseudo-anonymised data and could cause only a temporary voice outage.
  • Customer data: Rabbit says none was exposed in this event.
  • Wider: the R1 had already been criticised for not being ready at launch, 9to5Google notes. Rabbit committed to a third-party audit to confirm all historical secrets were revoked.

What this means for NHI and AI agent security

AI products are often thin layers over other providers' APIs: a speech model, a language model, a maps service. Each of those connections runs on an API key, a non-human identity that usually carries full access to the account it belongs to. The R1 depended on several, and they were written into the code. Once the code left Rabbit, through an insider according to the company, the keys went with it, and the only defence left was how quickly Rabbit could rotate them.

Two points stand out. First, the ElevenLabs key reached data generated by users' requests, so an AI provider's API key is also a key to customer interactions. Second, rotation caused an outage, a sign that the keys had no clean rotation path. Keeping provider keys in a secrets manager, scoping them per environment and rehearsing rotation would have made this a routine fix. Our LLMjacking Guide and API Key Management Guide cover these controls.

Recommendations

  • Rotate every key in leaked code, quickly and cleanly. Assume every secret in a leaked codebase is compromised, and design rotation so it does not take the product offline. See the Leaked Credential Response Playbook.
  • Move API keys out of source code. Store provider keys in a secrets manager and inject them at runtime. See our API Key Management Guide.
  • Block secrets at commit time. Add pre-commit and pipeline secret scanning so new keys cannot enter the codebase, and scan the full history for old ones.
  • Scope AI provider keys narrowly. Use separate, least-privilege keys per service and environment, and turn off history or logging features you do not need. See our LLMjacking Guide.
  • Plan for insiders. Limit who can copy production code and secrets, and remove access promptly when people leave. See our Insider Threat and Identity Guide.
  • Act on early warnings. Rabbitude claimed Rabbit knew about the keys before publication. Treat any report of exposed keys as an incident until the keys are rotated.

Frequently asked questions

What was the Rabbit R1 API key leak?

In June 2024 the Rabbitude group said Rabbit's source code contained hard-coded, working API keys for ElevenLabs, Azure, Yelp, Google Maps and an email service. Rabbit rotated the keys and later said an employee had leaked the code to the group.

Was Rabbit R1 user data exposed?

Rabbit says no customer data was exposed. It said the ElevenLabs key could reach bulk pseudo-anonymised data and that the only abuse it found was defamatory emails sent with the email key. Rabbitude claimed wider access to R1 responses.

How did Rabbitude get the Rabbit R1 source code?

Rabbitude said it gained access to the codebase on 16 May 2024. Rabbit said on 5 July 2024 that it had evidence an employee leaked a copy of the confidential internal code to the group, and that the employee was terminated.

xAI API Key Leak 2025 · LLMjacking 2024 to 2026 · Football Australia AWS Keys Exposure 2024 · API Key Management Guide · LLMjacking Guide

How NHI Mgmt Group can help

AI products run on other providers' API keys, and those keys are often the least governed identities in the stack. We help teams inventory them, move them out of code and rehearse rotation. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org