More than 543,000 credentials exposed in public GitHub repositories still worked when researchers checked them in July. Truffle Security’s findings show how GitHub credential leaks can leave access to services open long after developers publish sensitive information.
The exposed secrets had remained publicly accessible for a median of 784 days. Moreover, roughly 10% of the working credentials were older than 6.3 years, while the oldest dated back to 2009.
Large-Scale Scan Finds Long-Lived Secrets
Truffle Security examined 224 million repositories and more than 58 billion files. Its analysis used a dataset assembled for training large language models, with a crawl cutoff of August 7, 2025.
Researchers identified 543,699 unique, valid credentials. These appeared repeatedly across more than 1.1 million files and repositories, including copies in repository forks.
The crawl cutoff matters because the dataset represents a historical collection, rather than a complete view of GitHub at publication.
Meanwhile, the researchers found that secret density increased over time. Working credentials rose from 3.72 per million files in 2015 to a peak of 11.62 in 2025.
Push Protection Reduces Leaks Within Its Coverage
GitHub’s Push Protection checks incoming code for recognizable secrets, including supported API keys and access tokens. When it detects one, it can block the upload.
However, the feature does not revoke credentials that developers have already exposed.
Truffle Security found that 199,843 valid credentials first appeared after GitHub enabled Push Protection by default in February 2024. That represents approximately 36.8% of the total.
Additionally, 51.8% of the working credentials belonged to categories outside the default protection’s coverage. These included database connection strings and Google API keys.
Nevertheless, the researchers found a clear improvement among supported credential types. The exposure rate in protected categories fell by 53% after default enforcement began.
The findings therefore point to both the value of preventive scanning and the gaps that remain beyond its coverage.
Revocation Rates Vary Sharply Between Services
The study also revealed substantial differences in whether exposed credentials continued to work.
Among 101,886 exposed npm tokens, researchers found just one that remained valid. By comparison, 69,041 of 126,963 exposed Google Cloud service account credentials still worked during the analysis.
These contrasting results highlight why preventing new GitHub credential leaks addresses only part of the problem. Previously published secrets can remain usable until their owners or service providers invalidate them.
Removing a Secret Does Not Cancel Its Access
Truffle Security recommends promptly rotating exposed credentials, cleaning repositories and scanning their history for additional secrets. It also advises setting automatic expiration for active credentials.
Deleting sensitive information from the latest version of a file does not itself revoke the credential. Furthermore, earlier commits and forks may retain copies.
Although the research establishes widespread exposure of working secrets, it does not measure how many attackers stole or misused. Validity demonstrates potential access, while confirmed abuse requires separate evidence.


0 responses to “GitHub Credential Leaks Leave Over 543,000 Secrets Still Valid”