More than 543,000 credentials found in public GitHub repositories were still valid in July, according to research by Truffle Security, which scanned 224 million repositories and more than 58 billion files. The company counted 543,699 unique credentials that appeared repeatedly across more than 1.1 million files and repositories, including copies in forks. The figure covers working secrets that remained publicly accessible despite GitHub's efforts to stop accidental leaks.
Truffle Security found that the median time a unique credential stayed exposed was 784 days. About 10% of the working credentials were older than 6.3 years, and the oldest dated from 2009. The researchers also reported that secret density has grown over time, with working credentials rising from 3.72 per million files in 2015 to a peak of 11.62 in 2025.
The assessment used a dataset assembled to train large language models, based on a crawl that closed on August 7, 2025. Truffle Security said the number of exposed credentials on GitHub is more than double what it found in August after scanning Hugging Face, where it detected 221,303 working credentials.
GitHub introduced its Push Protection safeguard in April 2022 for Advanced Security users, made it available for public repositories in May 2023 and enabled it by default a year later. The mechanism scans incoming code for secret patterns such as API keys and access tokens and blocks the upload when it detects one, but it does not revoke credentials that were already exposed. Truffle Security reported that 199,843 of the credentials identified in July were exposed after GitHub activated Push Protection for all users in February 2024, about 36.8% of the total.
A little over half of the live credentials, 51.8%, fell into categories GitHub's default Push Protection does not block, including database connection strings and Google API keys. Within the categories it does cover, the feature appears effective: the rate of exposed credentials in protected categories fell by 53% after it was enabled by default.
Truffle Security said some credential types are far more likely to be revoked than others depending on the service. Of 101,886 committed npm tokens, the researchers found only one that still worked. By contrast, of 126,963 exposed Google Cloud service account credentials, 69,041 were still valid and working at the time of the analysis.
The practical recommendation for those affected is to rotate exposed credentials immediately, clean up repositories, scan history and set automatic expiration for all active secrets. Truffle Security's findings indicate the level and scale of working secret exposure on GitHub, but they do not reveal what percentage of those secrets are actually stolen and abused by attackers.
More software news from TechManNews.





