Truffle Security finds 543,000 live credentials still exposed in public GitHub repos
Truffle Security scanned 224 million GitHub repositories and 58 billion files, finding 543,699 unique valid credentials repeated across more than 1.1 million files and forks. The median exposure time was 784 days, with 10% of credentials older than 6.3 years and the oldest dating to 2009. The figure is more than double the 221,303 working credentials the firm previously found scanning Hugging Face.
GoKawiil's interpretation of the reporting above, not reported fact.
The findings suggest GitHub's Push Protection feature, meant to block secrets before they're committed, has limited effect once credentials are already public, since it does not revoke exposed keys. Truffle Security's data shows nearly 37% of the credentials found were exposed even after Push Protection became mandatory for all users in February 2024, indicating the safeguard may not be curbing long-term leakage as intended. Rising secret density over the past decade could point to growing risk as more code and training datasets scrape public repositories.
- 543,699 unique valid credentials were found across 1.1 million GitHub files and forks as of July.
- Median exposure time for a leaked credential was 784 days, with some dating back to 2009.
- Roughly 36.8% of exposed credentials appeared after GitHub's Push Protection became mandatory in February 2024.
YubiKey 5 Series Security Key — With hundreds of thousands of valid credentials leaking through code repositories, relying on static secrets alone is risky. A hardware security key like YubiKey adds a phishing-resistant layer of authentication for developer accounts and services, so even if a password or token leaks, an attacker still can't get in. It's a practical step for any developer serious about locking down GitHub and cloud service access.”}(cut)}]}
See YubiKey 5 Series Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-09-30
Published there as: “Over 543,000 valid credentials exposed in public GitHub repositories”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.