500,000 Active Credentials Left Exposed on GitHub
Truffle Security found 543,699 still-active credentials exposed in public GitHub repositories, many years old.
Truffle Security scanned 224 million public GitHub repositories in August 2025 and found 1,103,438 exposed credentials. Retesting at the end of July 2026 showed 543,699 were still active, with a median exposure of 784 days; one AWS key dated to 2009. Live secrets included 69,041 Google Cloud service accounts, 51,067 MongoDB connection strings, and 33,343 Google API keys. Nearly 199,843 credentials were pushed after GitHub’s default push protection, and GitHub does not require partner providers to revoke leaked tokens.
- Scan covered 224 million public GitHub repositories in August 2025.
- 543,699 of 1,103,438 exposed credentials were still active in July 2026.
- Median exposure was 784 days; an AWS key dates to 2009.
- Top live secrets: Google Cloud accounts, MongoDB strings, Google API keys.
- GitHub alerts and push protection did not force providers to revoke keys.
Full article376 words · extracted from securityweek.com · click to collapse
Truffle Security has discovered over half a million active unique credentials exposed in public GitHub repositories.
A total of 1,103,438 exposed credentials were discovered through the scanning of 224 million public GitHub repositories in August 2025.
At the end of July 2026, the security firm tested the credentials against their services and found that 543,699 of them were still active.
The oldest is an AWS key that was committed in 2009 and has remained untouched since. The median exposure window across the set is 784 days.
“2,636 live credentials come from files last modified before 2015. A quarter of everything we found is older than four years,” Truffle Security says.
The most concerning part is that nearly half of the credentials were pushed to the public repositories after GitHub enabled free alerts and default push protections to prevent the inadvertent exposure.
Advertisement. Scroll to continue reading.
“245,959 credentials predate free alerts. 97,897 arrived while scanning was free and push protection was one setting away. 199,843 landed after the block became the default, and were still answering to their providers more than two years later,” Truffle notes.
GitHub also runs a secret-scanning program that sends exposed tokens to the providers that issued them for revocation. However, it does not require partners to revoke the identified secrets, which explains the large number of credentials that remain active.
The list of exposed secrets is dominated by 69,041 Google Cloud service account credentials, 51,067 MongoDB connection strings, and 33,343 live Google API keys.
According to Truffle, the credentials remain active not because their exposure was not prevented, but because they were not revoked, as providers may not have a pipeline that kills the leaked tokens.
“Push protection is a good control and stops secrets at the door. It has nothing to say about the 543,699 already inside, and it was never meant to. Alerts do cover history, but only where an owner enabled them, read them, and then went and rotated the key,” Truffle notes.
Related: Malicious B-tree NPM Package Accumulates Millions of Downloads
Related: This Key Will Self-Destruct: An Open Standard for Revocable API Keys
Related: “We Think the Security Control Is Working” Is No Longer Good Enough
Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure