Truffle Security Finds 543,699 Still-Valid GitHub Credentials
Truffle Security says 543,699 unique credentials exposed in public GitHub repositories were still valid when retested on July 27–28, 2026.
Truffle Security analyzed The Stack v3 public-code corpus, scanning 224.55 million public GitHub repositories—also reported as 224 million—and more than 58 billion files in a crawl closed on August 7, 2025. Retesting on July 27–28, 2026 verified 543,699 unique credentials that still authenticated, recurring across 1,103,438 exposures in files and repositories, including forks; SecurityWeek instead describes 1,103,438 as exposed credentials found in the scan, of which 543,699 remained active at the end of July 2026. Median exposure on a public default branch was 784 days, and about 10 percent were older than 6.3 years. Sources disagree on the oldest secret: one report says a credential was last modified in June 2009, SecurityWeek specifies an AWS key from 2009, and another says the oldest still authenticated after 16.1 years. About 199,843 credentials, or 36.8 percent, were dated after GitHub enabled Push Protection by default in February 2024; protected categories fell 53 percent, 51.8 percent of live secrets used formats that protection does not block, and GitHub does not require partner providers to revoke leaked tokens. Of 126,963 exposed Google Cloud service-account credentials, 69,041 still worked, alongside 51,067 MongoDB connection strings, 33,343 Google API keys, and 31,374 Gemini keys; database strings, including PostgreSQL URIs that stayed valid 88 percent of the time, remained valid far more often than platform tokens, while only one of 101,886 npm tokens still worked and GitHub and Hugging Face tokens were almost entirely revoked. The study does not show how many secrets attackers actually abused.
- Truffle Security scanned The Stack v3: 224.55 million public GitHub repositories (also reported as 224 million) and more than 58 billion files; the crawl closed on August 7, 2025.
- Retests on July 27–28, 2026 found 543,699 unique credentials still valid, tied to 1,103,438 exposures; SecurityWeek instead treats 1,103,438 as the number of exposed credentials found.
- Median time on a public default branch was 784 days; about 10 percent were older than 6.3 years.
- Sources disagree on the oldest secret: June 2009 or a 2009 AWS key, versus continued authentication after 16.1 years.
- 199,843 credentials (36.8 percent) were dated after default Push Protection in February 2024; protected categories fell 53 percent, and 51.8 percent of live formats are not covered.
- Of 126,963 exposed Google Cloud service-account keys, 69,041 still worked, with 51,067 MongoDB strings, 33,343 Google API keys, and 31,374 Gemini keys also live.
- PostgreSQL URIs stayed valid 88 percent of the time; only one of 101,886 npm tokens remained valid, and GitHub and Hugging Face tokens were almost entirely revoked.
- The study does not show how many secrets attackers abused; GitHub does not require partner providers to revoke leaked tokens.
Coverage timelineoldest first · each row is one article
- · 1d agoOver 543,000 valid credentials exposed in public GitHub repositories
BleepingComputer· 74
Truffle Security found 543,699 still-valid credentials exposed in public GitHub repositories.
- · 11h agoOver 543,000 GitHub Credentials Remain Active After Being Publicly Exposed
Cyber Security News· 78
Truffle Security found 543,699 still-valid credentials exposed in public GitHub code.
- · 10h ago500,000 Active Credentials Left Exposed on GitHub
SecurityWeek· 68
Truffle Security found 543,699 still-active credentials exposed in public GitHub repositories, many years old.