TRUFFLE Security has revealed that more than half a million active, unique credentials were exposed in public GitHub repositories. In August 2025, researchers scanned 224 million public GitHub repositories and identified 1,103,438 exposed credentials. By the end of July 2026, their tests showed that 543,699 of these credentials were still active. The oldest item is an AWS key committed in 2009, and the median exposure window across the set is 784 days.
Among the exposed secrets, 69,041 are Google Cloud service account credentials, 51,067 are MongoDB connection strings, and 33,343 are live Google API keys.
A striking finding is that around 45% of the credentials were pushed to public repositories after GitHub had implemented push protections and free alerts intended to prevent inadvertent exposure. However, these protections do not revoke secrets or remove active credentials once they have already been exposed. GitHub’s secret-scanning program can notify providers to revoke leaked tokens, but it does not force revocation.
Truffle notes that push protection stops credentials at the “door,” but the older, already-exposed tokens may persist if providers’ revocation pipelines are incomplete or non-existent. Practically, organisations should rotate and revoke credentials discovered in public code, and rely on active monitoring and automated revocation workflows to reduce risk from long-lived exposure.