Truffle Security finds 543,699 active credentials exposed on GitHub
Truffle Security scanned 224 million public GitHub repositories and found 1,103,438 exposed credentials, of which 543,699 were still active as of July 2026. The oldest is an AWS key committed in 2009, and the median exposure window is 784 days. Nearly half of the leaks appeared after GitHub enabled free alerts and default push protection.
- 543,699 of 1,103,438 exposed credentials were still active in July 2026
- Median exposure window is 784 days; oldest is an AWS key committed in 2009
- 199,843 credentials leaked after push protection became the default
- Top exposures: 69,041 Google Cloud accounts, 51,067 MongoDB strings, 33,343 Google API keys
Read next
Security