500,000 Active Credentials Left Exposed on GitHub
Over 500,000 active credentials found exposed on public GitHub repositories.
Summary
Truffle Security discovered over 543,000 active credentials in public GitHub repositories, with many pushed even after GitHub enabled default push protections. The credentials, including Google Cloud service account credentials and MongoDB connection strings, remain active due to a lack of mandatory revocation by providers.
Full text
Truffle Security has discovered over half a million active unique credentials exposed in public GitHub repositories. A total of 1,103,438 exposed credentials were discovered through the scanning of 224 million public GitHub repositories in August 2025. At the end of July 2026, the security firm tested the credentials against their services and found that 543,699 of them were still active. The oldest is an AWS key that was committed in 2009 and has remained untouched since. The median exposure window across the set is 784 days. “2,636 live credentials come from files last modified before 2015. A quarter of everything we found is older than four years,” Truffle Security says. The most concerning part is that nearly half of the credentials were pushed to the public repositories after GitHub enabled free alerts and default push protections to prevent the inadvertent exposure.Advertisement. Scroll to continue reading. “245,959 credentials predate free alerts. 97,897 arrived while scanning was free and push protection was one setting away. 199,843 landed after the block became the default, and were still answering to their providers more than two years later,” Truffle notes. GitHub also runs a secret-scanning program that sends exposed tokens to the providers that issued them for revocation. However, it does not require partners to revoke the identified secrets, which explains the large number of credentials that remain active. The list of exposed secrets is dominated by 69,041 Google Cloud service account credentials, 51,067 MongoDB connection strings, and 33,343 live Google API keys. According to Truffle, the credentials remain active not because their exposure was not prevented, but because they were not revoked, as providers may not have a pipeline that kills the leaked tokens. “Push protection is a good control and stops secrets at the door. It has nothing to say about the 543,699 already inside, and it was never meant to. Alerts do cover history, but only where an owner enabled them, read them, and then went and rotated the key,” Truffle notes. Related: Malicious B-tree NPM Package Accumulates Millions of Downloads Related: This Key Will Self-Destruct: An Open Standard for Revocable API Keys Related: “We Think the Security Control Is Working” Is No Longer Good Enough Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come ForwardReco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksDutch Police Arrest Convicted Hacker in ShinyHunters InvestigationDaemon Tools Hackers’ NeedyMantis Malware Dissected by MicrosoftPrison Sentence for Former US Soldier Who Hacked AT&T and VerizonDC Health Agency Exposes 400,000 Beneficiary Records Latest News Cisco Patches Exploited Catalyst SD-WAN Zero-Day VulnerabilityGoogle Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersFTC is Investigating OpenAI and Anthropic Over Possible Risks to ConsumersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryWatchGuard Patches Critical Fireware OS Code Injection VulnerabilityGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksChrome, Firefox Updates Patch Over 100 VulnerabilitiesAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveDavid Cass has joined Grayscale Investments as Chief Risk Officer.Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.Alex Stamos has become Chief Information Security Officer at Cognition.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email