Researchers at Wake Forest University tested 444 AI chatbot apps on the US App Store and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic via plaintext API keys, reusable tokens, or backend servers that accepted requests with no authentication at all. Attackers who intercept these credentials can run model requests on the developer’s account and run up the bill; researchers estimated a worst-case scenario of tens of thousands of dollars in AI charges per day from a single stolen key. Affected apps spanned at least ten AI providers, including OpenAI and Google Gemini, across categories such as productivity and health. Three months after developers were notified, only 28% had fixed the issue.