Trusence Every claim has a source
Last updated 4 October 2026 Search Türkçe
← All stories
Security

Truffle Security finds 543,699 valid credentials still public on GitHub

The findings show that secret leaks can stay exposed for years even where GitHub’s Push Protection reduces some new exposure.

Truffle Security found 543,699 unique valid credentials still exposed in public GitHub repositories, showing that secret leakage remains a large and long-lived problem for developers and companies. The scan covered 224 million repositories and more than 58 billion files, and it found a median public exposure time of 784 days, with about 10% of working credentials older than 6.3 years. The oldest credential in the dataset dated to 2009, and the researchers said the count was more than double what they found in a separate August scan of Hugging Face. GitHub’s Push Protection appears to help for the secret types it covers, with protected-category exposures down 53% after default-on rollout, but it does not stop earlier leaks or revoke secrets that were already exposed.

Why it matters

For developers and companies, the main change is not that leaks exist, but how long they can remain usable after they are posted. A median public exposure time of 784 days, with some credentials dating back to 2009, means exposure can outlast the original mistake by years. GitHub’s default-on protection lowers exposure for covered secret types, but it does not fix older leaks already in public repositories.

Sources

  • BleepingComputer