PSA: My API key leaked in a public GitHub repo and someone ran up 4,000 calls on it
Honestly I messed up bad. I pushed a side project to GitHub back in March and left my Stripe key hardcoded in a config file, and within about 36 hours some bot was hammering it with test charges. I only caught it because my dashboard showed a spike to 4,000 API calls in one night, so I rotated the key, killed the repo, and set up a pre-commit hook to scan for secrets. Has anyone else dealt with a leak like this, and did you bother with GitHub secret scanning or just lock it down on your own?