Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Sourcegraph Breach 2023: How a Site-Admin Token Leaked…
Breach analysis Incident: 30 Aug 2023

Sourcegraph Breach 2023: How a Site-Admin Token Leaked in a Commit Became a Free LLM Proxy

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
Attack route: Leaked secret Identities: API key
On this page

On 30 August 2023, Sourcegraph, the maker of an AI-powered code search platform, disclosed that an attacker had used a leaked site-admin access token to take administrator control of its public Sourcegraph.com service. The token had been committed by a Sourcegraph engineer on 14 July 2023 in a code change to its public instance and was not caught by the company's automated code analysis. Forty-seven days later, on 30 August, a user who had created an account two days earlier used it to make themselves a site admin. The attacker then built a proxy app that let anyone call Sourcegraph's APIs and the large language model (LLM) behind its AI features, and handed out free access with raised rate limits. Sourcegraph spotted a surge in API usage and revoked the account the same day. It says license key recipients' names and emails, a small subset of license keys and free users' email addresses could have been seen, and that private code was not accessible.

Key takeaways

  • A Sourcegraph engineer committed an active site-admin access token on 14 July 2023; automated code analysis did not catch it, Sourcegraph says.
  • On 30 August 2023 an attacker used the token to promote a newly created account to site admin, 47 days after the leak, and reached the Sourcegraph.com admin dashboard.
  • The attacker created a proxy app allowing users "to directly call Sourcegraph's APIs and leverage the underlying LLM", and told people to request higher rate limits. Sourcegraph says the instructions drew close to 2 million views.
  • Sourcegraph confirmed the breach, rotated a subset of customer license keys and temporarily cut free-tier rate limits. It says there is no indication data was viewed, modified or copied, and that private code was not accessible.
  • The identity lesson: an admin token in source code is an admin login for anyone who reads the code, and on an AI platform it is also a key to someone else's LLM spend.

At a glance

OrganisationSourcegraph (the public Sourcegraph.com instance); its paying customers and free community users
WhenToken committed 14 July 2023; attacker account created 28 August 2023; admin access used, detected and revoked 30 August 2023; disclosed 30 August 2023
AttackerAn unidentified Sourcegraph.com user; no attribution has been published
Entry pointAn active site-admin access token included in a code commit to Sourcegraph's public instance
Identities abusedA Sourcegraph.com site-admin access token, used to elevate an ordinary account to site admin; free-tier user access tokens with raised rate limits
ImpactAdmin dashboard access; free LLM and API access offered through a proxy; possible view of license recipients' names and emails, a subset of license keys and free users' emails
CategoryNHI, LLM / AI platform. Incident class: confirmed NHI breach (leaked site-admin token used to take admin access and resell AI usage)

What happened

Sourcegraph makes code search tools with AI features, and GitGuardian describes it as "an AI-powered source code search engine". Its public Sourcegraph.com service is used by paying customers and free community users. On 14 July 2023 at 22:01 UTC, according to Sourcegraph's security update, an engineer accidentally committed a code change containing an active site-admin access token. Its internal controls, including automated code analysis, did not flag it, the company said. SecurityWeek reported that the token "had broad privileges to view and modify account information on Sourcegraph.com".

On 28 August a user created a new Sourcegraph.com account. On 30 August at 06:47 UTC that user used the leaked token to elevate the account to site admin and reach the admin dashboard. Sourcegraph says the attacker switched the account between admin and ordinary user several times while exploring. The attacker then, in Sourcegraph's words as quoted by SecurityWeek, "created a proxy app allowing users to directly call Sourcegraph's APIs and leverage the underlying LLM." The instructions told people to create free Sourcegraph.com accounts, generate access tokens and ask the attacker to raise their rate limits. Sourcegraph says the proxy app and instructions received close to 2 million views.

The spike in API usage gave the attacker away. Sourcegraph's security team noticed the increase on 30 August, identified the malicious site admin and revoked its access at 13:25 UTC, about six and a half hours after the escalation. The company published its security update the same day and updated it on 31 August.

Sourcegraph listed what the attacker could have seen: for paying customers, the names and email addresses of license key recipients and a small subset of license keys (the dashboard showed only the first 20 license key items on one page); for free users, account email addresses. "We have no indication that any of this data was viewed, modified, or copied," it said, and "No other customer info, including private code, emails, passwords, usernames, or other PII, was accessible." License keys do not grant access to customer instances, the company noted. It rotated the license keys that may have been viewed, temporarily reduced rate limits for free users, and said it was adding processes and expanding secret scanning.

Timeline

DateEvent
14 July 202322:01 UTC: a Sourcegraph engineer commits a code change containing an active site-admin access token; automated code analysis does not catch it.
28 August 202313:18 UTC: a user creates a new Sourcegraph.com account.
30 August 202306:47 UTC: the user elevates the account to site admin with the leaked token and gains admin dashboard access.
30 August 2023Sourcegraph notices a surge in API usage; at 13:25 UTC it identifies the malicious site admin and revokes access, then publishes a security update.
31 August 2023Sourcegraph updates its notice to clarify which license keys may have been viewed.
1 September 2023SecurityWeek reports the breach.

How it happened: the identity attack path

  1. Token committed to public code. An engineer included an active site-admin access token in a code change to Sourcegraph's public instance, and automated checks missed it.
  2. Token found and kept. Someone found the token in the 47 days it stayed exposed. Sourcegraph has not said how or when it was first copied.
  3. Privilege escalation with a stolen admin token. The attacker created an ordinary account, then used the token to promote it to site admin, gaining the admin dashboard.
  4. Monetising the AI platform. The attacker built a proxy that passed requests to Sourcegraph's APIs and LLM and used admin powers to raise rate limits for accounts that asked, spreading free AI access at Sourcegraph's expense.
  5. Detected by usage, not by the leak. The surge in API traffic triggered Sourcegraph's investigation and the admin account was revoked the same day.

Impact

  • Confirmed by Sourcegraph: an attacker held site-admin access to Sourcegraph.com for several hours, ran a proxy giving free access to its APIs and LLM, and could have seen license recipients' names and emails, a small subset of license keys and free users' email addresses.
  • Not found: Sourcegraph says it has no indication that this data was viewed, modified or copied, and that private code, passwords and other personal data were not accessible.
  • Cost and disruption: unpaid API and LLM usage through the proxy, rotation of some customer license keys and temporarily reduced rate limits for free users.

What this means for NHI and AI agent security

This is a classic leaked-secret breach with a newer motive. The credential was a long-lived, highly privileged access token placed in code, and it stayed valid for 47 days after it went public. What the attacker wanted was not customer data but the AI platform's compute: they turned Sourcegraph's LLM access into a free service and shared it widely. That is the same economics that drives LLMjacking, where stolen keys to AI services are resold or given away.

The lessons are to keep admin credentials out of code entirely, give them short lifetimes, and watch usage of AI features as closely as access to data, since a spike in model calls may be the first sign of a stolen credential. Our LLMjacking Guide and Secrets Management Guide cover both. Similar admin tokens exposed in code feature in the CrewAI GitHub token leak, and an organised scheme reselling stolen AI access appears in the Azure OpenAI abuse case of 2025.

Recommendations

  • Revoke an exposed token the moment it is found, and scan for it before that. Push protection and pre-commit hooks should block tokens, and anything that slips through should be revoked, not just deleted from the code. See the Leaked Credential Response Playbook.
  • Never put admin credentials in code. Load them at runtime from a secrets manager and give them the shortest workable lifetime. See our Secrets Management Guide.
  • Scope tokens to the task. A token that can promote any account to site admin should not exist for routine work. Use narrow, separately approved tokens for administrative actions. See our API Key Management Guide.
  • Alert on privilege changes. A new account becoming site admin should page someone immediately, regardless of which credential made the change. See our ITDR Guide.
  • Monitor AI and API usage for abuse. Set baselines and alerts for model calls and rate-limit changes, since unusual AI consumption is often the first sign of stolen access. See our LLMjacking Guide.
  • Rotate anything the attacker could have seen. Sourcegraph rotated license keys that may have been viewed; do the same for every secret visible from a compromised admin console.

Frequently asked questions

What happened in the Sourcegraph breach?

In August 2023 an attacker used a site-admin access token that a Sourcegraph engineer had accidentally committed on 14 July to promote their own account to site admin on Sourcegraph.com. They set up a proxy giving free access to Sourcegraph's APIs and LLM before Sourcegraph detected a usage spike and revoked access on 30 August.

Was customer data or code exposed in the Sourcegraph breach?

Sourcegraph says the attacker could have seen license key recipients' names and emails, a small subset of license keys and free users' email addresses, but that it has no indication this data was viewed, modified or copied. It says private code, passwords and other personal data were not accessible.

How long was the Sourcegraph token exposed before it was abused?

The token was committed on 14 July 2023 and used to gain site-admin access on 30 August 2023, 47 days later. Sourcegraph revoked the attacker's access about six and a half hours after the escalation, on the same day.

CrewAI GitHub token leak 2025 · Azure OpenAI abuse 2025 (Storm-2139) · LLMjacking 2024 to 2026 · LLMjacking Guide · Secrets Management Guide

How NHI Mgmt Group can help

Admin tokens in code and unmonitored AI usage are a common pairing in our breach database. We help organisations remove privileged secrets from code, shorten token lifetimes and put alerts on the privilege changes and AI consumption that reveal stolen access. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org