
Truffle Security scanned 224 million public GitHub repositories (more than 58 billion files) and found 543,699 unique credentials that still worked when it tested them in July. The median credential had been publicly readable for 784 days, about 10% were older than 6.3 years, and the oldest dated from 2009. The dataset comes from a crawl built to train language models that closed on August 7, 2025, and the same secrets often appeared across more than 1.1 million files and forks.
GitHub’s Push Protection, which blocks a commit that contains a recognizable secret, has been on by default for public repositories since February 2024. It helps: exposure in the categories it covers fell 53% afterward. But it does not revoke secrets that were already pushed, and 51.8% of the live credentials fell into categories it does not block by default, such as database connection strings and Google API keys. About 36.8% of the working credentials (199,843) were exposed after Push Protection became the default. Revocation also varies sharply by service: of 101,886 committed npm tokens only one still worked, while 69,041 of 126,963 exposed Google Cloud service account credentials were still valid. The research does not show how many of these secrets were actually found and abused by attackers.
How to check if you’re affected
Affected products are any API keys, tokens, database connection strings or cloud service account keys that have ever been committed to a public repository, including forks and old branches, by you, a contractor or a former employee. Rotate first, clean up second: deleting the file does not help because the secret stays in git history and in copies.
- Run a history-aware secret scanner such as TruffleHog (open source) against every repository and fork your organization controls, including personal accounts of current and former developers.
- Revoke and reissue any credential the scan reports as live, then check the provider’s access logs for use you do not recognize.
- Prefer short-lived credentials or set automatic expiry on all long-lived secrets.
- Enable Push Protection and secret scanning, and add custom patterns for the types it skips, such as connection strings.
