Decrypted: The UK Cyber Briefing
Oct 4, 2026 · 5 min · 6 segments
Truffle Security found 543,699 live credentials in public GitHub repositories, with a median exposure of 784 days. The gap between providers that revoke leaked keys and those that do not shows what…
Half a million working keys sit in public code, and some have been there since 2009.
A security firm has found more than half a million working passwords, keys, and tokens sitting in public code repositories.
The most uncomfortable number isn't the total, it's the age.
Truffle Security scanned two hundred and twenty-four million public GitHub repositories and found five hundred and forty-three thousand six hundred and ninety-nine unique credentials that still authenticated in July 2026.
The median one had been exposed for seven hundred and eighty-four days.
The oldest dated from 2009, and it still worked.
Next, what the researchers did.
They used the Stack V3, a data set assembled for training large language models.
Truffle matched known credential patterns, then tested each hit against the issuing provider on 27th and 28th July 2026.
A credential only counted if the provider confirmed it was live.
Those five hundred and forty-three thousand six hundred and ninety-nine secrets appeared one million, one hundred and three thousand four hundred and thirty-eight times because the same secret often gets copied around.
Think of a hotel that never recodes its room locks.
Guests leave, keys go missing, and nobody knows which doors they still open.
Committing a secret to a public repository is like leaving a key in a car park.
Deleting the file afterwards changes little.
The history keeps a copy, and the lock is still the same lock.
Half a million working keys sit in public code, and some have been there since 2009.
A security firm has found more than half a million working passwords, keys, and tokens sitting in public code repositories.
The most uncomfortable number isn't the total, it's the age.
Truffle Security scanned two hundred and twenty-four million public GitHub repositories and found five hundred and forty-three thousand six hundred and ninety-nine unique credentials that still authenticated in July 2026.
The median one had been exposed for seven hundred and eighty-four days.
The oldest dated from 2009, and it still worked.
Next, what the researchers did.
They used the Stack V3, a data set assembled for training large language models.
Truffle matched known credential patterns, then tested each hit against the issuing provider on 27th and 28th July 2026.
A credential only counted if the provider confirmed it was live.
Those five hundred and forty-three thousand six hundred and ninety-nine secrets appeared one million, one hundred and three thousand four hundred and thirty-eight times because the same secret often gets copied around.
Think of a hotel that never recodes its room locks.
Guests leave, keys go missing, and nobody knows which doors they still open.
Committing a secret to a public repository is like leaving a key in a car park.
Deleting the file afterwards changes little.
The history keeps a copy, and the lock is still the same lock.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.