Over 543,000 valid credentials exposed in public GitHub repositories

Over 543,000 valid credentials exposed in public GitHub repositories

More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform’s security measures to prevent accidental leaks of sensitive data.

Data pulled from scanning 224 million repositories and more than 58 billion files show that the median time a unique credential remained publicly accessible was 784 days.

The research was conducted by Truffle Security, which found that about 10% of the working credentials were older than 6.3 years and the oldest one dated from 2009.

In total, the researchers identified 543,699 unique credentials that appeared repeatedly across more than 1.1 million files and repositories, including copies in forks.

The assessment was conducted on a dataset assembled to train large language models, based on a crawl that closed on August 7, 2025.

Truffle Security says that the number of exposed credentials on GitHub exposure is more than double to what it found in August after scanning Hugging Face, where it detected 221,303 working credentials.

The researchers note that secret density has increased over time, with the number of working credentials rising from 3.72 per million files in 2015 to a peak of 11.62 in 2025.

Overview of Truffle's findings
Overview of Truffle’s findings
Source: Truffle Security

Push Protection effect

GitHub’s safeguard against accidentally leaking credentials, Push Protection, was introduced in April 2022 for Advanced Security users and became available for public repositories in May 2023. A year later, GitHub enabled it by default.

The mechanism scans incoming code for secret patterns like API keys and access tokens, and blocks the upload if it detects one. However, it does not revoke previously exposed credentials.

Truffle Security reports that 199,843 of the credentials identified in July were exposed after GitHub activated Push Protection for all users in February 2024, accounting for roughly 36.8% of the total.

A little over half (51.8%) of the live credentials fell into categories that GitHub’s default Push Protection does not block, including database connection strings and Google API keys.

However, Push Protection appears effective within its coverage: the rate of exposed credentials in protected categories fell by 53% after the feature was enabled by default.

Secrets exposure
Secrets exposure
Source: Truffle Security

Revocating exposed secrets

Looking at the dataset more broadly, Truffle says some credential types are a lot more likely to be revoked than others, depending on the service.

For example, of 101,886 committed npm tokens, the researchers found only 1 that still worked. In contrast, out of 126,963 exposed Google Cloud service account credentials, 69,041 were still valid and working at the time of the analysis.

The practical recommendation for those affected is to immediately rotate exposed credentials, clean up repositories, scan history, and set automatic expiration for all active secrets.

Truffle’s Security findings indicate the level and scale of working secret exposure on GitHub, but they don’t reveal what percentage of those secrets are actually stolen and abused by attackers.

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat