Security0 views

Over 543,000 Exposed GitHub Credentials Remain Valid for Years

More than 543,000 credentials exposed across 1 million public GitHub files and repositories remained valid through July, with roughly 10% older than 6 years and the oldest dating back to 2009. Researchers found that exposed credentials stay publicly accessible for an average of 784 days before being revoked or rotated.

The analysis covered 224 million repositories and more than 58 billion files through August 7. Most alarming: the rate of valid credentials per million files has surged 212% between 2015 and 2025, signaling an accelerating problem. The sheer volume and longevity of exposed credentials underscore how widely secrets are committed to public repositories—often accidentally—and how slowly organizations detect and remediate them.

This finding reinforces the critical need for secret scanning tools, pre-commit hooks to block credential uploads, and regular credential rotation. Organizations should assume that any secret committed to a public repository has been compromised and act accordingly, even if no active misuse has been detected yet.