Truffle Security scanned a dataset built from 224 million repositories and more than 58 billion files. I took the counts from their post and from BleepingComputer. They found 543,699 unique credentials that still worked as of the July check, repeated across more than 1.1 million files including forks. Median time in the open: 784 days. The oldest live secret dated to 2009.

About 36.8 percent of the live set was committed after GitHub turned on Push Protection for everyone in February 2024. npm tokens were almost all dead. 69,041 of 126,963 Google Cloud service-account credentials still worked.

Push Protection is a bouncer for new commits in covered categories. It does not revoke what already leaked, and it misses whole classes such as database URLs and some Google keys. A private fork does not hide a secret that already sat in history. I scan the repos I actually ship from, rotate anything that ever sat in git, and put expiry on new keys.