Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

500,000 Active Credentials Left Exposed on GitHub

Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.

Leaked credentials

Truffle Security has discovered over half a million active unique credentials exposed in public GitHub repositories.

A total of 1,103,438 exposed credentials were discovered through the scanning of 224 million public GitHub repositories in August 2025.

At the end of July 2026, the security firm tested the credentials against their services and found that 543,699 of them were still active.

The oldest is an AWS key that was committed in 2009 and has remained untouched since. The median exposure window across the set is 784 days.

“2,636 live credentials come from files last modified before 2015. A quarter of everything we found is older than four years,” Truffle Security says.

The most concerning part is that nearly half of the credentials were pushed to the public repositories after GitHub enabled free alerts and default push protections to prevent the inadvertent exposure.

Advertisement. Scroll to continue reading.

“245,959 credentials predate free alerts. 97,897 arrived while scanning was free and push protection was one setting away. 199,843 landed after the block became the default, and were still answering to their providers more than two years later,” Truffle notes.

GitHub also runs a secret-scanning program that sends exposed tokens to the providers that issued them for revocation. However, it does not require partners to revoke the identified secrets, which explains the large number of credentials that remain active.

The list of exposed secrets is dominated by 69,041 Google Cloud service account credentials, 51,067 MongoDB connection strings, and 33,343 live Google API keys.

According to Truffle, the credentials remain active not because their exposure was not prevented, but because they were not revoked, as providers may not have a pipeline that kills the leaked tokens.

“Push protection is a good control and stops secrets at the door. It has nothing to say about the 543,699 already inside, and it was never meant to. Alerts do cover history, but only where an owner enabled them, read them, and then went and rotated the key,” Truffle notes.

Related: Malicious B-tree NPM Package Accumulates Millions of Downloads

Related: This Key Will Self-Destruct: An Open Standard for Revocable API Keys

Related: “We Think the Security Control Is Working” Is No Longer Good Enough

Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

David Cass has joined Grayscale Investments as Chief Risk Officer.

Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.

Alex Stamos has become Chief Information Security Officer at Cognition.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.