Truffle Security Finds 543,699 Credentials Still Valid in Public GitHub Repositories, With a Median Exposure of 784 Days
A scan of 224 million public repositories found 543,699 working credentials; GitHub push protection cut protected-type leaks by 53 percent but 51.8 percent of live secrets fall outside it.
Overview
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform’s leak-prevention measures, according to BleepingComputer, which reported on research by Truffle Security. In its own write-up, dated September 29, 2026, Truffle Security said it found 543,699 unique credentials that still authenticated when tested in July 2026, with a median age of 784 days in a public default branch.
What We Know
The scan. Truffle Security says it scanned a snapshot of public GitHub code assembled to train AI models, The Stack v3, covering 224,553,295 repositories and 58,467,468,698 files, according to Truffle Security. The company says it tested each candidate credential against the issuing service between 27 and 28 July 2026, and that the dataset’s crawl closed on 7 August 2025. The corpus keeps only each repository’s default branch as it stood at crawl time, so it contains no commit history, and the researchers used each file’s last-modification timestamp as the leak date, per the same write-up.
Age. The oldest live credential was last touched on 13 June 2009 and was still valid 16.1 years later, according to Truffle Security. It is a set of database credentials inside an Erlang web server configuration. Truffle Security said it is not naming the repositories because the credentials still work.
Density. Truffle Security reports that the number of live credentials per million files was 3.72 in 2014, 9.54 in 2022 and 11.09 in 2023, and reached 11.62 in 2025, the highest in the dataset (Truffle Security). It described the 543,699 figure as more than double the 221,303 working credentials it found in an earlier scan of Hugging Face training data.
Push protection. GitHub turned push protection on by default on 29 February 2024, according to Truffle Security. Of the live credentials, 199,843, roughly 36.8 percent, were exposed after GitHub activated it for all users in February 2024, as reported by BleepingComputer. Truffle Security’s comparison across the twelve months either side of the rollout found that the protected group of credential types fell 53 percent and the unprotected group fell 7 percent. BleepingComputer wrote that push protection “appears effective within its coverage”.
The coverage is the limit. Truffle Security says 51.8 percent of every live credential in the corpus is a connection string, a Google API key or a private key, none of which are blocked by default. It also found 31,374 live Gemini API keys, with a median leak date of February 2025. The researchers add that GitHub’s secret scanning partner program forwards a leaked token to its issuer but “does not require partners to revoke anything” (Truffle Security).
Revocation decides survival. Truffle Security’s per-provider counts show wide differences in how many leaked credentials stayed alive (Truffle Security):
- npm tokens: 101,886 committed, 1 still live.
- GitHub tokens: 73,048 committed, 260 still live.
- Google Cloud service accounts: 126,963 committed, 69,041 still live.
- Postgres connection strings: 12,985 committed, 11,465 still live.
The researchers wrote that what separates the families is whether the provider has a pipeline that takes a leaked token and kills it, summarizing: “Nobody revokes a Postgres URL, and almost everything does.”
Recommendations. Truffle Security advises: “Treat a committed credential as burned the moment it lands, whether or not anything flagged it. Rotate first, clean up the history second.” It also recommends scanning one’s own history, preferring credentials that expire on their own, and checking whether a provider participates in a revocation programme.
What We Don’t Know
- BleepingComputer notes that the findings “don’t reveal what percentage of those secrets are actually stolen and abused by attackers.”
- Truffle Security lists its own caveats: the separation after the rollout is a ramp from March to July 2024 rather than a step on 29 February, and a concurrent industry shift toward short-lived credentials “cannot be ruled out” as a contributing factor (Truffle Security).
- Because the dataset keeps no commit history and relies on file timestamps, leak dates are approximations; the company says this errs toward making credentials look younger than they are.
- The figures come from a single vendor’s analysis of a single dataset; neither source cites an independent replication.