Over Half a Million Valid Credentials Exposed on GitHub, Many Unrevoked for Years
A new report from **Truffle Security** reveals that more than 543,000 valid credentials remain exposed in public **GitHub** repositories, with some dating back over a decade. Despite **GitHub**'s 'Push Protection' efforts, a significant number of active secrets continue to be publicly accessible, posing substantial security risks to organizations and individual users.
A recent analysis by **Truffle Security** has uncovered a startling number of active credentials lingering in public **GitHub** repositories. The research, which involved scanning 224 million repositories and over 58 billion files, identified 543,699 unique, valid credentials that were still exposed as of July. This figure is more than double the number of working credentials found in a previous scan of **Hugging Face**.
The median duration for a unique credential to remain publicly accessible was a staggering 784 days. Alarmingly, approximately 10% of these active credentials were older than 6.3 years, with the oldest identified credential dating back to 2009.

**Truffle Security**'s findings indicate a rising trend in secret density over time. The number of working credentials per million files increased from 3.72 in 2015 to a peak of 11.62 in 2025, highlighting an escalating challenge in managing sensitive data within codebases.

### The Impact of Push Protection
**GitHub** introduced 'Push Protection' to prevent accidental credential leaks, rolling it out for **Advanced Security** users in April 2022 and making it available for public repositories in May 2023. By February 2024, **GitHub** enabled this feature by default for all users.
This mechanism scans incoming code for secret patterns, such as **API** keys and access tokens, and blocks uploads if detected. However, it does not revoke credentials that were already exposed prior to the commit.
**Truffle Security**'s report indicates that 199,843 of the identified credentials, roughly 36.8% of the total, were exposed *after* **GitHub** activated Push Protection for all users. Furthermore, over half (51.8%) of the live credentials fell into categories not covered by **GitHub**'s default Push Protection, including database connection strings and **Google API** keys.
Despite these gaps, Push Protection has shown some efficacy within its scope. The rate of exposed credentials in protected categories reportedly fell by 53% after the feature was enabled by default.
.jpg)
### The Critical Need for Revocation
**Truffle Security**'s broader analysis reveals varying revocation rates across different credential types. For instance, out of 101,886 committed **npm** tokens, only one remained functional. In stark contrast, 69,041 out of 126,963 exposed **Google Cloud** service account credentials were still valid and working at the time of the analysis.
These findings underscore the critical importance of proactive credential management. The practical recommendations for organizations and developers include immediately rotating any exposed credentials, thoroughly cleaning repositories, scanning commit history for past exposures, and implementing automatic expiration policies for all active secrets.
While **Truffle Security**'s research highlights the extensive scale of working secret exposure on **GitHub**, it does not quantify the percentage of these secrets that have been actively compromised or exploited by malicious actors. Nevertheless, the sheer volume of unrevoked, valid credentials presents a significant attack surface that demands immediate attention from the cybersecurity community.