Truffle Security Finds 543,699 Working Credentials in Public GitHub Repositories
Security / news
Truffle Security Finds 543,699 Working Credentials in Public GitHub Repositories
The median leaked secret had sat in a public repository for 784 days, and GitHub push protection covers only part of what leaks.

Truffle Security found 543,699 unique credentials that still worked in public GitHub repositories, with a median exposure of 784 days, according to a report it published. The company validated each one against its issuing service on July 27 and 28, 2026.
These are live credentials in public repositories: keys that authenticate, not keys anyone is known to have abused. The report counts access that exists, not access that was taken. Truffle scanned 224 million public repositories, and the figures are its own; The Terminal could not independently verify them.
How old the leaked credentials are
The Hacker News, in a bulletin covering the study, quoted Truffle's line that "the median one had been sitting in a public default branch for 784 days. The oldest was committed in 2009 and still works."
Truffle splits the 543,699 by when the credential was committed, against GitHub's own protection milestones. The largest group predates GitHub's free secret alerts.
- Before free alerts (Feb. 2023)246K credentials
- Alerts available, push protection optional (Feb. 2023 to Feb. 2024)98K credentials
- Push protection on by default (Feb. 2024 on)200K credentials
Source: Truffle Security, validated July 27 and 28, 2026
The last bar is the awkward one. Nearly 200,000 working credentials, 36.8 percent of the total, were pushed after GitHub made push protection the default in February 2024.

Why push protection leaves half of them through
Truffle says push protection cut new exposure by about 53 percent for the patterns it recognizes. It only blocks vendor-prefixed tokens, the kind whose format identifies the issuer. Truffle puts the credentials outside that net at 51.8 percent of every live one, mostly database connection strings, Google API keys and private keys.
A string like postgres://user:password@host/db has no prefix to match, which is why it passes.
Which credentials die and which survive
Truffle's survival rates split by whether the provider has automated revocation. npm tokens show 0.001 percent survival: one live token out of 101,886 committed. GitHub's own tokens survive at 0.36 percent.
| Credential type | Share still live |
|---|---|
| npm tokens | 0.001% |
| GitHub tokens | 0.36% |
| MySQL connection strings | 75% |
| PostgreSQL connection strings | 88% |
The gap is the finding: types with automated revocation almost never show up live, and database strings mostly do. Truffle's advice is to "treat a committed credential as burned the moment it lands" and rotate it, instead of relying on scanning or blocking.
What to check first
On Truffle's numbers, the practical order is to rotate database connection strings and Google API keys first, since those are the types push protection does not block and the PostgreSQL and MySQL strings are the ones most often still live.
Credentials in a developer's reach are also the target in attacks we have covered, such as a fake NDA branch that carried a git post-checkout hook and the agent-sandbox work around NVIDIA's OpenShell. Truffle's July snapshot is the figure to compare against if it publishes a follow-up.
Sources
More in Security
- 01NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload DownloadCitrix patched a SAML memory overflow on October 3 and 4 after attacks began. CISA gave agencies until October 7, and the appliances patched last week for CVE-2026-88771 through CVE-2026-88778 need updating again.
- 02Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No WorkaroundCisco's PSIRT found exploitation during a support case in September. Six release trains have fixes, and the vendor and two security firms count Cisco's earlier SD-WAN flaws differently.
- 03Two Zammad Zero-Days Took an Attacker From Session Hijack to Root at the Dutch Institute for Vulnerability DisclosureCISA put CVE-2026-102489 and CVE-2026-102490 in its exploited catalog on October 2. DIVD says an AI agent, not a person, ran the intrusion it found on its own ticketing system.
- 04Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the PatchCVE-2026-88771 and CVE-2026-88772 both score 9.5. Citrix shipped fixed builds on September 27, but researchers say implants planted earlier persist through the update.