543,699 Valid Credentials Found Exposed in Public GitHub Repositories
More than 543,000 credentials published in GitHub’s public repositories were still valid as of July, despite the platform’s security measures designed to prevent the accidental exposure of sensitive data.
The findings come from a scan of 224 million repositories and more than 58 billion files. Researchers found that unique credentials remained publicly accessible for a median of 784 days.
The study, conducted by Truffle Security, identified approximately 10% of valid credentials as being more than 6.3 years old. The oldest credentials dated back to 2009.
In total, researchers identified 543,699 unique credentials appearing repeatedly across more than 1.1 million files and repositories, including copies stored in repository forks.
The evaluation used a dataset collected to train a large-scale language model. The underlying crawl ended on August 7, 2025.
According to Truffle Security, the number of publicly exposed credentials found on GitHub is more than double the number identified in August, when a scan of Hugging Face found 221,303 valid credentials.
The researchers also found that the density of exposed secrets has increased over time. The number of valid credentials rose from 3.72 per million files in 2015 to a peak of 11.62 per million files in 2025.

Source: Truffle Security
GitHub push protection reduced some credential leaks
GitHub introduced push protection, its defense against accidental credential disclosure, for Advanced Security users in April 2022. The feature became available for public repositories in May 2023, and GitHub enabled it by default a year later.
Push protection scans incoming code for secret patterns, including API keys and access tokens, and blocks uploads when it detects them. However, the feature does not revoke credentials that were published previously.
Truffle Security reports that 199,843 of the credentials identified in July were exposed after GitHub enabled push protection for all users in February 2024. That represents approximately 36.8% of the total.
Just over half of the live credentials—51.8%—belonged to categories that GitHub’s default push protections do not block, including database connection strings and Google API keys.
Within the categories covered by push protection, however, the feature appears to be effective. After it was enabled by default, the rate of credential exposure in protected categories fell by 53%.
.jpg)
Source: Truffle Security
Many exposed GitHub secrets were never revoked
Looking at the dataset more broadly, Truffle Security says some credential types are much more likely to be revoked than others.
For example, only one of the 101,886 npm tokens committed to repositories was still functional. In contrast, 69,041 of the 126,963 exposed Google Cloud service account credentials remained valid and operational at the time of the analysis.
Organizations affected by exposed credentials should immediately rotate them, remove secrets from repositories, scan repository history, and configure automatic expiration for all active credentials.
Truffle Security’s findings demonstrate the scale of work-secret exposure on GitHub. However, the study does not reveal what percentage of the exposed credentials were actually stolen or misused by attackers.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



