Skip to content

security: remove hardcoded Infura API key from debug scripts - #363

Merged
jhfnetboy merged 4 commits into
masterfrom
security/scrub-hardcoded-infura-key
Jun 24, 2026
Merged

jhfnetboy merged 4 commits into
masterfrom
security/scrub-hardcoded-infura-key

Conversation

@jhfnetboy

Copy link
Copy Markdown
Member

What

aastar/check-account.js and aastar/test-userop-hash.js hardcoded a Sepolia Infura API key inside the RPC URL. Replaced both with process.env.ETH_RPC_URL (public-RPC fallback) — the scripts still run, no secret embedded.

⚠️ Rotation still required (this PR is not enough)

This repo is public and the leaked credentials are already in git history (e.g. commits ca83890, and an earlier ecosystem.config.js fallback now removed by 4e736cb). Removing them from the tree does not undo the exposure. The following must be rotated/revoked out-of-band:

  • Infura API key 7051eb37… — rotate in Infura
  • ETH_PRIVATE_KEY 0x72966a3f… — revoke + move any funds (in history)
  • Pimlico API key pim_gcVkL… — rotate in Pimlico

Surfaced by the PR-daemon review of #104 (already merged). Current ecosystem.config.js is already clean (reads process.env); this PR clears the last in-tree copy.

check-account.js and test-userop-hash.js hardcoded a Sepolia Infura API key
in the RPC URL. Replaced with process.env.ETH_RPC_URL (public-RPC fallback) so
the scripts still run without embedding a secret.

NOTE: the key is already exposed in this public repo's git history (and was also
present in an earlier ecosystem.config.js fallback), so it MUST be rotated in the
Infura dashboard — removing it from the tree does not undo the exposure. The
ETH_PRIVATE_KEY and Pimlico key that also appear in history must be rotated too.
@jhfnetboy
jhfnetboy requested a review from fanhousanbu as a code owner June 24, 2026 01:10
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Scans the repo for private keys / API keys on push + PR to main/master/develop
(complements the local pre-commit hook). Installed via LeakShield.
scripts/security/scrub-history.sh purges the 3 leaked credentials from git
history via git-filter-repo. Secrets are extracted from history at runtime (not
hardcoded), written to a .git-local replacements file, and deleted after.

Dry-run by default; --run rewrites history (then force-push + collaborators
re-clone). Clearly marked: rotation is mandatory regardless — scrubbing a public
repo's history does NOT undo the exposure.

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

clestons review — #363 [2-round, APPROVE]

security: remove hardcoded Infura API key from debug scripts — security housekeeping following the credentials exposure in #104. 4 files.

Verified ✅

  • Key removal confirmed: check-account.js and test-userop-hash.js both had -const RPC_URL = "https://sepolia.infura.io/v3/7051eb377c..." removed and replaced with process.env.ETH_RPC_URL (public-RPC fallback). No hardcoded secrets remain in these files.
  • CI secret scanner (.github/workflows/check-secrets.yml): covers 8 generic patterns — 0x[a-fA-F0-9]{64} (ETH private keys), BEGIN.*PRIVATE KEY (PEM), AKIA… (AWS), sk-… (OpenAI/Anthropic), gh[pousr]_… (GitHub PAT), sk_(live|test)_… (Stripe), api_key = "..." — this is broad coverage, not just these specific leaked keys. Future leaks will be caught generically.
  • scrub-history.sh: correctly notes that tree-removal is not enough and provides git-filter-repo instructions. PR body includes explicit rotation guidance for all 3 credentials.
  • Secret scan of this PR itself: clean.

Note (Info): scrub-history.sh mentions 0x075F227E… but the leaked private key was 0x72966a3f…. Verify the correct key is used in the git history scrub command.

APPROVE. Keys correctly replaced with process.env references; CI scanner adds ongoing protection with generic patterns. Rotation of all 3 credentials (Infura / ETH_PRIVATE_KEY / Pimlico) remains a required out-of-band action.

…tes32)

LeakShield's 0x[a-fA-F0-9]{64} pattern can't distinguish a private key from a
legitimate bytes32 (hashes, storage slots, calldata, test fixtures) — it flagged
many false positives across the repo, making the check permanently red. Keeping
the Infura-key removal + history-scrub script here; the detection-quality fix
(context-aware matching) goes upstream to LeakShield first, then we re-adopt.
@jhfnetboy
jhfnetboy merged commit 21cc938 into master Jun 24, 2026
11 checks passed
@jhfnetboy
jhfnetboy deleted the security/scrub-hardcoded-infura-key branch June 24, 2026 01:50
@github-actions github-actions Bot locked and limited conversation to collaborators Jun 24, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants