Truffle Security has unveiled that more than 500,000 active credentials are publicly accessible in GitHub repositories. This discovery highlights significant vulnerabilities in securing sensitive information.
Vast Scope of Exposure
In August 2025, a thorough examination of 224 million public repositories on GitHub revealed a startling 1,103,438 exposed credentials. By July 2026, the firm verified that 543,699 of these were still valid and operational.
Among the exposed credentials, an AWS key dating back to 2009 remained active, illustrating long-term security oversights. The median duration for which the credentials were exposed was 784 days, indicating persistent vulnerabilities in data protection.
Challenges in Credential Management
A significant portion of these credentials were found in files last updated before 2015, with 2,636 still active. Approximately 25% of the exposed credentials are over four years old, suggesting a need for regular audits and updates.
Despite GitHub’s efforts to mitigate exposure through free alerts and default push protections, nearly half of these credentials were added to repositories after such measures were implemented. This raises concerns about the effectiveness and adoption of these security practices.
Efforts and Future Considerations
GitHub’s secret-scanning initiative aims to notify providers of exposed tokens for revocation. However, the lack of mandatory revocation results in many credentials remaining active. Notably, Google Cloud service accounts, MongoDB connection strings, and Google API keys were predominant among exposed credentials.
Truffle Security highlights that the persistence of these active tokens is not due to a lack of preventive measures but rather the absence of effective revocation processes. This emphasizes the need for improved collaboration between GitHub and service providers to bolster security protocols.
As the digital landscape evolves, ensuring robust credential management is crucial for protecting sensitive information. Continuous monitoring and proactive measures are essential for mitigating risks associated with exposed credentials.
