The AI Post
Agents & CodingOpen ModelsEnterpriseFundraisingGenerative MediaGovernanceInferenceInfrastructureLegal & SafetySector Impact
← Front Page Security · Truffle Security · GitHub · npm · Google Cloud

Study finds 543,699 leaked GitHub credentials that still work, one from 2009

Truffle Security tested secrets in 224 million public repositories and found over half a million still valid. Most Google Cloud service keys survive, while almost no npm tokens do.

Truffle Security said it found 543,699 unique credentials that still authenticate, after scanning 224 million public GitHub repositories. The oldest working secret dates from 2009. The median one had sat in a public default branch for 784 days, the company's report says, and it tested them in July 2026.

The repositories came from a dataset assembled to train language models, built from a crawl that closed on 7 August 2025. Truffle said Google API keys with Gemini access were the most common live secret, at 69,041. The company has not said how many of the affected keys were exploited, and the count is of keys that work, not keys that were abused.

How long a leak survives depends on the provider. Truffle found 0.001% of leaked npm tokens still worked, because npm revokes them automatically. GitHub's own tokens survived at 0.36%. Among Google Cloud service accounts, 54% still worked, and 88% of leaked Postgres connection strings did, since neither has an equivalent revocation mechanism.

GitHub's push protection, on by default since February 2024, roughly halves how often covered credentials reach public code, Truffle said. But 51.8% of what remains live is a format it does not recognise, mostly connection strings and Google API keys. Truffle's advice is to treat any committed credential as compromised and rotate it, whatever the alerts say.

Sources 2 sources

  1. Source Truffle Security
  2. Source BleepingComputer