Site navigation

Developers Exposed Nearly 13 million Secrets on GitHub Last Year

Michael Edgar

,

92% of Devs Using AI Coding Tools, New GitHub Survey Finds GiHub secrets
A new report shows developers accidentally exposed 12.8 million secrets on public GitHub repositories last year. 

A stark revelation from GitGuardian, a code security platform, unveiled a concerning surge in developers inadvertently leaking sensitive information on public GitHub repositories. According to GitGuardian, this new figure is a 28% increase from the previous year, indicating a worrisome trend in data security negligence within the developer community. 

This number, the report points out, has quadrupled since 2021. It also points out that seven out of every 1000 commits, 4.6% of active repositories, and a staggering 11.7% of contributing authors inadvertently disclosed at least one secret last year.

Despite issuing 1.8 million alert emails during this period, the report revealed that a staggering 90% of exposed secrets remained active five days post-leakage, and just a mere 2.6% were revoked within one hour of notification via email.

“Developers erasing leaky commits or repositories instead of revoking are creating a major security risk for companies, which will remain vulnerable to threat actors mirroring public GitHub activity for as long as the credential remains valid. These zombie leaks are the worst,” said Eric Fourrier, CEO and founder of GitGuardian.

The report identifies the types of secrets exposed, identifying Google API keys, MongoDB credentials, OpenWeatherMap tokens, Telegram Bot tokens, Google Cloud keys, and AWS IAM as the most commonly leaked. 

Unveiling the sectors most culpable for leaking secrets, the IT sector emerged as the worst offender, accounting for a staggering 65.9% of the total breaches. It was closely followed by education, science & technology, retail, manufacturing, and finance and insurance.


Recommended reading


Furthermore, GitGuardian claims to have detected a staggering 1212-fold increase in OpenAI API key leaks and observed a rise in leaked HuggingFace user access tokens, underscoring the burgeoning popularity of AI services and the concomitant security risks associated with their usage.

In light of these alarming findings, GitGuardian emphasised the importance not only to detect but also to address these leaks promptly. The report stressed that while detection is crucial, effective remediation hinges on providing developers with guidance and support to correct their errors quickly.

Michael Edgar

Staff Writer, DIGIT

Latest News

Cybersecurity Featured Security

Proposed Police Scotland Cyber Centre Raises Duplication Questions

Cybersecurity Editor's Picks Events

Microsoft, NBCUniversal and Admiral Group Experts Set for CymruSec 2026

AI Business Editor's Picks

Salesforce Agentforce Bugs Exposed Wider AI Agent Risk, Research Finds

AI Cybersecurity

Despite AI Hype, Traditional Identity Fraud Prevails