← All stories
● Covered by 2 sources · 2 reportsMedium impact1 negative1 neutral

Over 543,000 Valid Credentials Exposed in Public GitHub Repositories

🔄 Updated 1d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 543,699 valid credentials found in public GitHub repos.
  • Median exposure time for credentials was 784 days.
  • GitHub's Push Protection blocks new leaks but not old ones.
  • 199,843 credentials exposed after Push Protection was enabled.
  • 51.8% of live credentials are not covered by default Push Protection.
  • Truffle Security found 1,103,438 exposed credentials by scanning 224 million public GitHub repositories.
  • Scanning occurred in August 2025.
  • Truffle Security tested credentials against services at the end of July 2026.
  • The oldest exposed credential is an AWS key committed in 2009.
  • 2,636 live credentials are from files last modified before 2015.
  • A quarter of found credentials are older than four years.
  • 245,959 credentials predate free alerts.
  • 97,897 credentials arrived while scanning was free and push protection was one setting away.

Hundreds of Thousands of Valid Credentials Exposed

Truffle Security's research revealed that more than 543,000 valid credentials were publicly exposed in GitHub repositories as of July. These credentials remained active despite GitHub's security measures. The data was gathered by scanning 224 million repositories and over 58 billion files, showing a median exposure time of 784 days for unique credentials. Some credentials were over 6.3 years old, with the oldest dating back to 2009.

Comparison to Other Platforms and Secret Density

The number of exposed credentials on GitHub is more than double what Truffle Security found on Hugging Face, where 221,303 working credentials were detected in August. The research also indicates an increasing trend in secret density over time, with working credentials rising from 3.72 per million files in 2015 to a peak of 11.62 in 2025.

Effectiveness of GitHub's Push Protection

GitHub introduced Push Protection in April 2022 for Advanced Security users, expanding it to public repositories in May 2023 and enabling it by default a year later. This feature scans incoming code for secret patterns and blocks uploads if detected. However, it does not revoke previously exposed credentials. Truffle Security reported that 199,843 of the identified credentials were exposed after Push Protection was activated for all users in February 2024, representing about 36.8% of the total. Additionally, 51.8% of the live credentials fell into categories not blocked by GitHub's default Push Protection, such as database connection strings and Google API keys. Despite these limitations, Push Protection reduced the rate of exposed credentials in covered categories by 53% after its default activation.

Challenges in Credential Revocation

The study also observed varying rates of credential revocation depending on the service. For instance, out of 101,886 committed npm tokens, only one remained active. This contrasts with other credential types, indicating that some services are more proactive or efficient in revoking leaked secrets than others.

Updates

🕒 2026-10-01 · new reporting from SecurityWeek
  • Truffle Security found 1,103,438 exposed credentials by scanning 224 million public GitHub repositories.
  • Scanning occurred in August 2025.
  • Truffle Security tested credentials against services at the end of July 2026.
  • The oldest exposed credential is an AWS key committed in 2009.
  • 2,636 live credentials are from files last modified before 2015.
  • A quarter of found credentials are older than four years.
  • 245,959 credentials predate free alerts.
  • 97,897 credentials arrived while scanning was free and push protection was one setting away.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Truffle Security identified 543,699 active credentials exposed in public GitHub repositories, despite GitHub's secret scanning and push protection features. This exposure highlights a gap in credential revocation processes by providers, as many of these secrets remain valid years after being committed.

A study by Truffle Security found over 543,000 valid credentials exposed in public GitHub repositories, with some remaining accessible for years. This highlights that GitHub's Push Protection, while effective for new exposures in covered categories, does not revoke existing leaked credentials and misses certain types of secrets.