Your safety profile is now part of the free plan. Tell us what you use, and we'll customize your alerts and guidance to match your online life.Build My Profile
MERENA
Immediate Action Alert

Hackers are using a flaw in Langflow to steal passwords, tokens, and secret keys

A serious flaw in Langflow, a tool used to build AI apps, is being actively abused to break into exposed systems and steal account secrets such as OpenAI and Amazon cloud keys. People and organizations using Langflow should act quickly because stolen keys can let criminals access services, run up charges, or take more data.


Who is at risk

Developers, companies, and anyone running Langflow—especially internet-exposed setups tied to OpenAI, Amazon cloud, or other connected services—are most at risk.

What to watch for

Watch for unexpected charges, unfamiliar activity in connected cloud or AI accounts, new or changed access keys, and systems running Langflow that are reachable from the internet.

What to do

Immediately update Langflow to the latest fixed version, remove public access if possible, and replace any OpenAI, AWS, or other service keys that may have been exposed.