Possible API Key Leak? Need Input
I’ve been tracking something strange and I need to know if anyone else has experienced this.
Whenever I hold a large amount of cash, I get mugged almost immediately. At first I assumed it was normal mug bots. But after testing, the pattern became too consistent to ignore.
Here are the logs:
05:02:19 - 12/02/26
Quavo mugged you for $13,759,470 sending you to the hospital for 0h 45m
After this, I deleted my API key (which I was using for Torn PDA and Tornstats).
After deleting the key:
01:34:21 - 25/02/26
Quavo mugged you for $0 sending you to the hospital for 0h 38m
05:14:26 - 12/02/26
Quavo mugged you for $3,321 sending you to the hospital for 0h 40m
He was still trying, but clearly no longer hitting large amounts.
Then I generated a new API key and logged back into PDA and Tornstats.
Shortly after my faction sent war payout:
04:41:40 - 03/03/26
Quavo mugged you and stole $3,870,162
The timing is what’s concerning.
Delete API key → large muggings stop.
Create new API key → large mugging resumes immediately after payout.
I’m not accusing any specific app, but something isn’t adding up. If anyone else has noticed similar behavior after connecting third-party apps, please share.
If this is an API vulnerability issue, it needs attention. We trust these apps with our keys and that trust shouldn’t expose us.