Major Security Breach: 500,000 Active Credentials Exposed on GitHub

www.news4hackers.com-major-security-breach-500-000-active-credentials-exposed-on-github-major-security-breach-500-000-active-credentials-exposed-on-github

Truffle Security identified over 543,000 active credentials still functional in public GitHub repositories after scanning 224 million repositories in August 2025.

Key Findings

Truffle Security identified over 543,000 active credentials still functional in public GitHub repositories after a comprehensive scan of 224 million repositories in August 2025. A follow-up test conducted in July 2026 confirmed the persistence of these credentials, with 1,103,438 exposed secrets initially detected.

Timeline of Exposure

The dataset includes an AWS access key committed in 2009 that remained unaltered for over 17 years. The average duration between initial exposure and verification was 784 days. Analysis revealed 2,636 credentials modified in files last updated before 2015, with 25% of the total dataset comprising credentials older than four years.

GitHub’s Security Measures

The timeline of exposure aligns with GitHub’s implementation of security measures, including free secret alerts and push protection policies. Of the identified credentials, 245,959 predated the introduction of free alerts, 97,897 were exposed during the period when scanning was free but push protection was optional, and 199,843 were uploaded after push protection became mandatory.

Persistence of Credentials

Despite these safeguards, 543,699 credentials remained active two years after the default protections were enforced. GitHub’s secret-scanning program automatically notifies issuers of exposed tokens for potential revocation, but this process is not mandatory. As a result, 69,041 Google Cloud service account credentials, 51,067 MongoDB connection strings, and 33,343 active Google API keys persisted in public repositories.

The firm emphasized that push protection prevents new secrets from entering repositories but has no effect on credentials already present. Alert systems only mitigate risks when users actively monitor notifications and rotate compromised keys.

Systemic Challenges

The findings highlight systemic challenges in managing exposed credentials, particularly with legacy secrets and insufficient enforcement of revocation protocols. The data underscores the limitations of reactive security measures in addressing long-standing vulnerabilities within public code repositories.


Blog Image

About Author

en_USEnglish