Skip to content
Tech News
← Back to articles

Truffle Security finds 543,000 live credentials still exposed in public GitHub repos

read original get YubiKey 5 Series Security Key → more articles
GoKawiil Brief

Truffle Security scanned 224 million GitHub repositories and 58 billion files, finding 543,699 unique valid credentials repeated across more than 1.1 million files and forks. The median exposure time was 784 days, with 10% of credentials older than 6.3 years and the oldest dating to 2009. The figure is more than double the 221,303 working credentials the firm previously found scanning Hugging Face.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The findings suggest GitHub's Push Protection feature, meant to block secrets before they're committed, has limited effect once credentials are already public, since it does not revoke exposed keys. Truffle Security's data shows nearly 37% of the credentials found were exposed even after Push Protection became mandatory for all users in February 2024, indicating the safeguard may not be curbing long-term leakage as intended. Rising secret density over the past decade could point to growing risk as more code and training datasets scrape public repositories.

Key Takeaways
Worth a Look

YubiKey 5 Series Security Key — With hundreds of thousands of valid credentials leaking through code repositories, relying on static secrets alone is risky. A hardware security key like YubiKey adds a phishing-resistant layer of authentication for developer accounts and services, so even if a password or token leaks, an attacker still can't get in. It's a practical step for any developer serious about locking down GitHub and cloud service access.”}(cut)}]}

See YubiKey 5 Series Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-30

Published there as: “Over 543,000 valid credentials exposed in public GitHub repositories”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.