More than half a million credentials exposed in public GitHub repositories are still live, according to a new analysis by security firm Truffle Security, which scanned 224 million public repos and found 1,103,438 exposed secrets.

When the company tested those credentials against their issuing providers at the end of July 2026, 543,699 still worked. The oldest is an AWS key committed in 2009 and untouched since; the median exposure window across the whole set is 784 days, and 2,636 live credentials come from files last modified before 2015.

The finding that has security teams most concerned is timing: roughly 199,843 of the credentials were pushed to public repositories after GitHub made push protection the default. In other words, the block at the door did not clean up what was already inside. Another 97,897 arrived while scanning was free and push protection was one setting away.

The raw material is mundane — 69,041 exposed Google Cloud service-account credentials, 51,067 MongoDB connection strings and 33,343 live Google API keys dominate the list. The common thread is not that the secrets were missed but that they were never revoked; providers are not obliged to act on the tokens GitHub reports to them.

'Push protection is a good control and stops secrets at the door. It has nothing to say about the 543,699 already inside, and it was never meant to,' Truffle Security wrote, arguing that alerts only work where someone reads them and then rotates the key.

The practical takeaway for developers and platform teams: prevention and remediation are different problems. Turning on push protection stops new leaks, but the exposed credentials already sitting in repository history need to be rotated, not merely flagged.