Truffle Security (29 Sep): 543,699 still-valid credentials in public GitHub (Stack v3) — median 784 days exposed
Truffle Security research (published 29 September 2026; BleepingComputer amplify 30 Sep) scanned The Stack v3 public-code corpus used to train AI models (crawl closed 7 August 2025): 224.5M repositories / ~58.5B files. Between 27–28 July 2026 they verified candidates against issuers and found 543,699 unique credentials still authenticating — more than double the 221,303 live secrets in their prior Hugging Face training-data scan. Median public exposure age 784 days; oldest commit 2009 still working; 1.1M+ file/repo exposures including forks. ~199,843 (~36.8%) were exposed after GitHub enabled Push Protection by default (Feb 2024); Push Protection cut exposure rate ~53% in covered categories, but 51.8% of still-live secrets are shapes it does not block (e.g. DB connection strings, Google API keys). Example contrast: 1/101,886 npm tokens still live vs 69,041/126,963 Google Cloud service-account credentials still valid. Guidance: rotate exposed secrets, purge history, scan forks, set short expirations. Not a single-vendor CVE — org secrets-hygiene story. Primary: Truffle blog 29 Sep; wire: BleepingComputer 30 Sep.
- Product
- Public GitHub repositories / org secrets (API keys, cloud SA keys, DB strings, tokens)
- Versions
- n/a — corpus snapshot Stack v3 (crawl closed 7 Aug 2025); live verification Jul 2026
- Exploited in Australia?
- unknown
- Patch to
- No CVE. Rotate any secret that ever hit a public default branch (incl. forks/history); enable/extend secret scanning + push protection; block uncovered secret shapes (DB URLs, Google API keys); short-lived credentials; periodic TruffleHog/org secret scans of public repos and training-data mirrors.
Primary: Truffle Security — GitHub repos exposed 543,699 credentials (29 Sep 2026) · Vendor: Truffle Security research (primary) · BleepingComputer — Over 543,000 valid credentials on public GitHub (30 Sep 2026)
