Eigen RadarAI
Analysis

Credentials and proxy access in AI automation

Two reports show leaked n8n API tokens still opening live workflow systems, while the Poison Claude proxy that resells discounted model access can read every prompt before forwarding it.

Artificial Intelligence··Evening
In a bright synthetic atrium, a luminous stream passes through a woven blue membrane and divides between a rectangular amber gate and a circular iris, with a blank translucent disc in front.

What leaked n8n tokens exposed

GitGuardian found 4576 unique n8n API tokens in files committed to public GitHub repositories since April 2025. The tokens mapped to 1255 hostnames; 896 were publicly reachable, and 321 still accepted at least one leaked token. That amounted to 36 percent of the reachable instances and 26 percent of all identified hostnames. The tokens most often appeared beside instance addresses in .env files and in Claude Code permission files at .claude/settings.json. Many carried no expiry, so they remained valid until revoked; 7 of the 372 Model Context Protocol tokens were also valid. Using only documented REST endpoints, the researchers enumerated accounts and workflow definitions. They invoked stored credentials against external services such as OpenAI without reading the credential values directly, read data tables containing names, email addresses and form responses, and configured a workflow that sent raw credential values to an outside address.[1]

Poison Claude's proxy arrangement

The Poison Claude report describes a commercial arrangement in which access is handed to an intermediary infrastructure through a different route. According to Okta researchers Jeremy Kirk and Mathew Woodyard, the service pools free AWS Bedrock bonus credits and sells access to Anthropic models for 5 percent to 15 percent of the official per-token price. A customer receives an Anthropic-compatible API key and points environment variables at the operator's infrastructure. The operator then routes each request to one of the pooled accounts without showing the customer which account is being used. Because that infrastructure sits between the prompt and the model as a proxy, the operator can read every submitted prompt before forwarding it. The service's own description says each account carries 100 dollars of free credit. A misconfigured endpoint also exposed a counter showing 881 total and 872 active users when the service was discovered. The report includes no statement from Anthropic about the service.[2]

Two different paths to access

The common element is that access to an artificial intelligence system passes through credentials and routing layers before reaching the model provider. In the n8n instances, a leaked token authorized documented endpoints in automation environments that had already been configured to connect databases, repositories, cloud services and model providers. Under the Poison Claude arrangement, a customer deliberately directs requests to a third party to obtain discounted access, and that intermediary can see the request content. The first report concerns long-lived tokens exposed in public repositories; the second concerns a proxy service operating through pooled accounts, so the two routes to access are materially different. GitGuardian said n8n acknowledged the reports, stated that it planned to address them and closed them, while no released fix had been independently confirmed at publication. The Poison Claude report likewise contains no statement from Anthropic. Those response limits leave the technical access described by the reports unchanged; they constrain what is known about the operators' responses and remediation status.[1], [2]

References

  1. News sourceThe Hacker NewsLeaked n8n tokens opened 321 live automation instances↩1↩2
  2. News sourceThe Hacker NewsA proxy resells Claude access and reads every prompt on the way↩1↩2