Over 543,000 valid credentials exposed in public GitHub repositories
Over 543,000 valid credentials were found exposed in public GitHub repositories as of July 2025, despite GitHub's security measures like Push Protection. These credentials include API keys, access tokens, database connection strings, and cloud service account credentials. The median exposure time for a unique credential was 784 days, with some credentials dating back to 2009. Push Protection, introduced in 2022 and enabled by default in 2024, has reduced exposure rates for certain credential types but does not revoke previously exposed secrets or cover all credential categories. The exposed credentials pose a risk if not rotated or revoked promptly.
AI Analysis
Technical Summary
Research by Truffle Security analyzed 224 million GitHub repositories and over 58 billion files, identifying 543,699 unique credentials repeatedly exposed across more than 1.1 million files and repositories. Despite GitHub's Push Protection feature scanning for secret patterns and blocking uploads, many credentials remain valid and publicly accessible. Approximately 36.8% of exposed credentials were committed after Push Protection was enabled for all users, and over half of the live credentials fall into categories not covered by Push Protection, such as database connection strings and Google API keys. Credential revocation rates vary by service; for example, npm tokens are mostly revoked, while many Google Cloud service account credentials remain active. The study highlights the ongoing risk of credential exposure on GitHub and recommends immediate rotation and cleanup of exposed secrets.
Potential Impact
The exposure of valid credentials in public repositories can lead to unauthorized access to services, data breaches, and potential misuse of cloud resources or APIs. The long median exposure time increases the window of opportunity for attackers. Although GitHub's Push Protection reduces new exposures in covered categories, it does not revoke existing credentials or cover all secret types, leaving many credentials vulnerable. The impact varies by credential type and service, with some credentials more likely to be revoked than others.
Mitigation Recommendations
Affected users and organizations should immediately rotate any exposed credentials, clean up repositories and their histories to remove secrets, and implement automatic expiration policies for active secrets. GitHub's Push Protection helps prevent new exposures for certain secret types but does not revoke existing credentials, so manual remediation is necessary. Regular scanning for exposed secrets and prompt response remain critical.
Over 543,000 valid credentials exposed in public GitHub repositories
Description
Over 543,000 valid credentials were found exposed in public GitHub repositories as of July 2025, despite GitHub's security measures like Push Protection. These credentials include API keys, access tokens, database connection strings, and cloud service account credentials. The median exposure time for a unique credential was 784 days, with some credentials dating back to 2009. Push Protection, introduced in 2022 and enabled by default in 2024, has reduced exposure rates for certain credential types but does not revoke previously exposed secrets or cover all credential categories. The exposed credentials pose a risk if not rotated or revoked promptly.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Research by Truffle Security analyzed 224 million GitHub repositories and over 58 billion files, identifying 543,699 unique credentials repeatedly exposed across more than 1.1 million files and repositories. Despite GitHub's Push Protection feature scanning for secret patterns and blocking uploads, many credentials remain valid and publicly accessible. Approximately 36.8% of exposed credentials were committed after Push Protection was enabled for all users, and over half of the live credentials fall into categories not covered by Push Protection, such as database connection strings and Google API keys. Credential revocation rates vary by service; for example, npm tokens are mostly revoked, while many Google Cloud service account credentials remain active. The study highlights the ongoing risk of credential exposure on GitHub and recommends immediate rotation and cleanup of exposed secrets.
Potential Impact
The exposure of valid credentials in public repositories can lead to unauthorized access to services, data breaches, and potential misuse of cloud resources or APIs. The long median exposure time increases the window of opportunity for attackers. Although GitHub's Push Protection reduces new exposures in covered categories, it does not revoke existing credentials or cover all secret types, leaving many credentials vulnerable. The impact varies by credential type and service, with some credentials more likely to be revoked than others.
Defensive Guidance
Affected users and organizations should immediately rotate any exposed credentials, clean up repositories and their histories to remove secrets, and implement automatic expiration policies for active secrets. GitHub's Push Protection helps prevent new exposures for certain secret types but does not revoke existing credentials, so manual remediation is necessary. Regular scanning for exposed secrets and prompt response remain critical.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6abd52912a4e24523d5abf5c
Added to database: 09/30/2026, 18:18:57 UTC
Last enriched: 09/30/2026, 18:19:03 UTC
Last updated: 10/01/2026, 04:18:03 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.