GitHub watch for those and notify the provider of the API key so it can be revoked, as well as emailing the owner(s) of the repo which contained the key.
if it was in enough places that it got reproduced exactly via neural network, then there is zero chance it escaped their secret-scanners.
they even have some GHAS feature that lets you define your own regexes for secrets and will notify you if any are found.
none of this makes it safe to store secrets in code, though, these things just help tell you when you've done it.