If a malicious party has access to the API key, it should be revoked regardless
In other words I don't have your key, or any key, but I have "all of them".
The correct response to this though is that "there are lots of keys, and valid keys are sparse."
In other words the jumper of valid keys that could be invalidated in this way is massively smaller than the list of invalid keys. Think trillions of trillions to 1.
People could just hit important data fetch endpoints with random keys, until they find one that’s good, and then have a compromised account.