Half a million GitHub secrets are still live and unrevoked

Truffle Security found more than half a million still-valid credentials exposed in public GitHub repositories.

CSBadmin
2 Min Read

More than 500,000 credentials that developers left behind in public GitHub repositories can still be used today, long after anyone noticed them.

Truffle Security looked at 224 million public repositories in August 2025 and logged 1,103,438 exposed secrets. The firm checked the same tokens against their issuing services at the end of July 2026, and 543,699 of them still worked. One AWS key was committed back in 2009 and nothing has touched it since, and a median exposure window of 784 days stretches across the full set.

“2,636 live credentials come from files last modified before 2015,” Truffle wrote. “A quarter of everything we found is older than four years,” the firm added.

What bothers the researchers most is how many secrets arrived after GitHub began helping. Nearly half of the exposed credentials were pushed after the platform turned on free alerts and default push protection. Within that group, 97,897 landed while scanning was free but push protection was one setting away, and 199,843 showed up once blocking became the default, yet providers still answered for them more than two years later.

Among the still-live secrets, 51,067 are MongoDB connection strings, 33,343 are Google API keys, and 69,041 are Google Cloud service account credentials. GitHub’s secret-scanning program alerts issuing providers, but nothing forces them to revoke a token, the gap Truffle blames for the backlog. “Push protection is a good control and stops secrets at the door,” the firm noted. “It has nothing to say about the 543,699 already inside.”

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.