Over 543,000 valid credentials exposed in public GitHub repositories

More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform’s security measures to prevent accidental leaks of sensitive data.
Data pulled from scanning 224 million repositories and more than 58 billion files show that the median time a unique credential remained publicly accessible was 784 days.
The research was conducted by Truffle Security, which found that about 10% of the working credentials were older than 6.3 years and the oldest one dated from 2009.
In total, the researchers identified 543,699 unique credentials that appeared repeatedly across more than 1.1 million files and repositories, including copies in forks.
The assessment was conducted on a dataset assembled to train large language models, based on a crawl that closed on August 7, 2025.
Truffle Security says that the number of exposed credentials on GitHub exposure is more than double to what it found in August after scanning Hugging Face, where it detected 221,303 working credentials.
The researchers note that secret density has increased over time, with the number of working credentials rising from 3.72 per million files in 2015 to a peak of 11.62 in 2025.
Overview of Truffle's findingsSource: Truffle Security
Push Protection effect
GitHub's safeguard against accidentally leaking credentials, Push Protection, was introduced in April 2022 for Advanced Security users and became available for public repositories in May 2023. A year later, GitHub enabled it by default.
The mechanism scans incoming code for secret patterns like API keys and access tokens, and blocks the upload if it detects one. However, it does not revoke previously exposed credentials.
Truffle Security reports that 199,843 of the credentials identified in July were exposed after GitHub activated Push Protection for all users in February 2024, accounting for roughly 36.8% of the total.
A little over half (51.8%) of the live credentials fell into categories that GitHub's default Push Protection does not block, including database connection strings and Google API keys.
However, Push Protection appears effective within its coverage: the rate of exposed credentials in protected categories fell by 53% after the feature was enabled by default.
Secrets exposureSource: Truffle Security
Revocating exposed secrets
Looking at the dataset more broadly, Truffle says some credential types are a lot more likely to be revoked than others, depending on the service.
For example, of 101,886 committed npm tokens, the researchers found only 1 that still worked. In contrast, out of 126,963 exposed Google Cloud service account credentials, 69,041 were still valid and working at the time of the analysis.
The practical recommendation for those affected is to immediately rotate exposed credentials, clean up repositories, scan history, and set automatic expiration for all active secrets.
Truffle’s Security findings indicate the level and scale of working secret exposure on GitHub, but they don't reveal what percentage of those secrets are actually stolen and abused by attackers.
References in this story
- Hundreds of leaked AWS keys give full control over corporate accounts www.bleepingcomputer.com More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.
- GitHub can now auto-block commits containing API keys, auth tokens www.bleepingcomputer.com GitHub announced on Monday that it expanded its code hosting platform's secrets scanning capabilities for GitHub Advanced Security customers to automatically block secret leaks.
- GitHub now can auto-block token and API key leaks for all repos www.bleepingcomputer.com GitHub is now automatically blocking the leak of sensitive information like API keys and access tokens for all public code repositories.
- GitHub enables push protection by default to stop secrets leak www.bleepingcomputer.com GitHub has enabled push protection by default for all public repositories to prevent accidental exposure of secrets such as access tokens and API keys when pushing new code.
- GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them. ◆ Truffle Security Co. trufflesecurity.com We scanned 224 million public GitHub repositories. Half of the credentials that still work had been exposed for more than two years, and the oldest since 2009.



