Truffle Security reports that 543,699 credentials discovered in public GitHub data still authenticated when tested. The finding comes from the company’s analysis of The Stack v3, a dataset containing 224.6 million public repositories and 58.47 billion files, and points to a long-lived operational problem rather than only recent accidental disclosure.
Scale and age of the exposure
The researchers identified 1,103,438 exposed credential candidates and tested them on July 27 and 28, 2026. They said 543,699 remained live. The median exposure age was 784 days, while the oldest valid credential dated to 2009. These figures are research findings reported by Truffle Security and should be understood within the methodology described in its primary report.
The study also found 199,843 live credentials exposed after GitHub enabled default push protection in February 2024. According to the report, 51.8 percent of live credentials used formats that default push protection did not block. For teams managing broader cyber-physical security risks, the result illustrates how software supply-chain weaknesses can create access paths into operational environments.
Control implications for security teams
The research indicates that preventive scanning alone does not close the exposure window. Organizations need detection across repositories and development workflows, but they also need a reliable process to revoke and replace discovered secrets. Historical repositories and older commits deserve attention because a credential’s age does not establish that it has expired. Asset owners should treat a confirmed live credential as an incident requiring containment, scope assessment, rotation, and a review of associated access rather than merely removing the visible string from a repository.

Leave a Reply