Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Credential security

Over 543,000 Valid Credentials Found in Public GitHub Repositories

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Truffle Security found 543,699 unique credentials that still worked when checked in July 2026, among data drawn from a historical crawl of public GitHub repositories. The figure is not a live count for October 2026, and a credential testing valid does not show that an attacker found or used it. The findings, reported by BleepingComputer on September 30, 2026, highlight both how long secrets can remain accessible and the limits of GitHub’s default Push Protection.

What does the 543,699 figure measure?

Truffle Security examined a dataset assembled for large language model training from a crawl that ended August 7, 2025. The analysis covered 224 million repositories and more than 58 billion files. In July 2026, the researchers checked credentials found in that data and identified 543,699 unique credentials that were still valid, according to BleepingComputer’s report.

The corpus date and the credential-check date are different: the underlying crawl closed in August 2025, while the validity checks took place in July 2026. The count therefore describes credentials in that historical dataset that worked when tested. It is not a real-time inventory of GitHub on October 2, 2026, and it does not mean that all 543,699 credentials were exposed continuously or accessible in the same way.

The report says these credentials appeared repeatedly across more than 1.1 million files and repositories, including forks. The number of unique credentials is not the same as the number of appearances or affected repositories.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How long did credentials remain exposed?

The median time a unique credential remained publicly accessible was 784 days, according to Truffle Security’s 2026 analysis. About 10% of the working credentials were older than 6.3 years; the oldest identified credential dated to 2009.

These figures help explain why age alone is not a reliable sign that a leaked secret has become harmless. Whether a credential still works depends on the service and on whether someone revoked, rotated, or expired it.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Does GitHub Push Protection prevent secret exposure?

Push Protection scans incoming code for recognized secret patterns and can block a push containing a match. BleepingComputer reports that it was enabled by default in February 2024. Truffle Security found a 53% decline in exposure rates for credential types covered by Push Protection after default enablement. That reduction applies to covered categories, not to every kind of secret.

The report found 199,843 credentials—36.8% of the total—that were exposed after Push Protection became enabled by default. This does not establish that each exposure involved a blocked push or a successful bypass. Coverage limitations matter, and Push Protection cannot revoke a credential that has already been exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

In the analysis, 51.8% of working credentials belonged to categories the default protection did not block, including database connection strings and Google API keys. Pattern-based detection can only protect against formats it recognizes; a secret outside that coverage can still be committed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why do validity rates differ by service?

The report’s examples show sharply different outcomes across credential types:

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Credential type Exposed credentials checked Still valid
npm tokens 101,886 1
Google Cloud service account credentials 126,963 69,041

These are counts reported by Truffle Security for the study, not a general expiration rate for either service. They show why teams should verify and revoke a particular exposed credential rather than assume it is either still usable or already expired.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What should you do if a secret was committed publicly?

  1. Revoke or rotate the credential first. Removing the text from the latest version of a file does not disable an active credential. Use the credential provider’s controls to invalidate it or replace it.
  2. Check repository history and copies you control. Search previous commits as well as the current working tree, and include organization-controlled repositories and forks where applicable. A secret deleted from the latest commit may remain in older history.
  3. Clean up the repository separately. After revocation or rotation, remove the exposed value from the repository as appropriate. Repository cleanup and credential invalidation are distinct tasks.
  4. Set expiration where supported. Automatic expiration limits how long an active secret can remain usable if it is exposed and goes unnoticed.
  5. Use Push Protection as one layer, not the whole response. It can block recognized patterns on incoming pushes, but the reported study found working credentials in categories outside its default coverage.
  6. Distinguish exposure from confirmed abuse. The study measured whether credentials were valid, not whether attackers discovered or used them, or whether organizations were compromised. Establishing misuse requires separate evidence.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.