More than half a million passwords, keys and tokens sit in public GitHub code and still work. Truffle Security, which makes tools for finding leaked secrets, tested them in July and found 543,699 unique credentials that still let it log in.

Developers sometimes paste a database password or an API key into their code and publish it by mistake. Anyone can then use it. The study shows that many of these keys are never switched off.

Years in the open

The team scanned 224 million public repositories from The Stack v3, a snapshot of public code collected to train AI models. The median live credential had been visible for 784 days. Half had been public for more than two years, and the oldest since 2009.

It depends on the service

What happens after a leak depends mostly on who issued the key. Services that automatically revoke leaked keys, such as npm and GitHub itself, had fewer than 1 percent still working. For Postgres and MySQL database passwords, which no one revokes automatically, 75 to 91 percent still worked. Of Google Cloud service account keys, 54 percent were alive.

GitHub has blocked known kinds of secrets before they are published since February 2024, a feature called push protection. Truffle says it cut new leaks of the covered kinds by about half. But 51.8 percent of the live credentials are of kinds it does not cover, such as database connection strings.

The advice

Truffle's advice is to treat any credential that reached a public repository as stolen. Push protection only watches new commits, so old history needs its own scan.

Expiring keys are the safer default, the company says.