Security1 distinct publisher3 min readUpdated
Truffle Security retested 10,616 publicly leaked AWS credentials and 88 percent still authenticated. The median key was about five years old and had no successor.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The load-bearing number here is 10,616, not 9,300. That is the count of keys for which Truffle Security held the full credential pair and could actually attempt authentication [7]. The wider haul, 64,024 unique keys mapping to 50,654 accounts [6], is untested for validity, because an access key ID without its secret cannot be tried. So the roughly 9,342 keys that answered on August 10 [8][1] represent about one key in six from the corpus [2], and the honest reading is a floor, not a measurement of how much of the exposure is live.
What keeps a key answering for that long shows up in the age data. Of the 2,903 keys with creation dates, about 4.5 percent of the unique set, the median was 1,831 days old and the oldest had existed for 17.4 years [12][7]. Only 398 of those users had a newer key issued alongside the old one [13]. Rotation is not merely slow at this scale; for this population it mostly does not happen. The practical expiry date of a leaked key is the deletion of the IAM user that owns it.
The privilege breakdown deserves reading with a pencil. Truffle counts 817 company-linked keys with 526 root keys among them [2], plus 242 IAM users carrying AdministratorAccess [3]. 526 and 242 add to the 768 keys the researchers describe as full control of a company's AWS account [4][6]. That sum treats the root and administrator sets as disjoint while the 817 figure uses a different denominator, and the write-up does not reconcile them. Either way, the count of keys with nothing between the holder and the account runs into the high hundreds.
Then the detection question. Of 2,754 accounts whose metadata could be read, 262 had a budget alert configured [9], which is 9.5 percent [3]. Cryptomining on stolen credentials is a billing event before it is a security event [16], and roughly nine accounts in ten here have no tripwire on the bill.
The Hugging Face concentration is the supply-chain part. 8,482 unique key exposures came from that platform [10], 13.2 percent of every unique key in the study [4], and Truffle puts the root share of that set at 17.9 percent [11], on the order of 1,518 root keys from a single source [5]. Datasets and model artifacts are not code review targets in most shops, and they are being published with working cloud credentials inside them.
Truffle says its testing stopped at read-only metadata and that it notified every owner it could identify [15]. Its own advice is to delete root access keys outright and treat anything committed to a public source as compromised [14]. The 88 percent figure is what the last five years of not doing that looks like when someone finally tests it.
Ranked by verification strength, evidence, and original report placement.
The subset for which researchers had complete credentials usable for re-verification was 10,616 keys.
More than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 are still active and valid.
Truffle Security has tracked the exposure for the past four years and says 817 of the exposed keys were linked to companies, 526 of them being AWS root keys.
242 of the keys are associated with IAM users holding the AdministratorAccess policy, which has full permissions to create, modify, delete and view virtually all AWS services and resources in an account.
The researchers state that each of the 768 live keys in the two sets gives full control of a company's AWS account.
Truffle Security found 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries and CI logs.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Quantified vendor research, single secondary account
The numbers are specific, internally consistent and accompanied by a stated methodology and ethical scope (read-only metadata, owner notification), which is stronger than a typical vendor teaser. But everything in the cluster traces to one outlet relaying one vendor's unpublished-in-cluster report: there is no primary methodology document, no independent replication, no AWS or Hugging Face response, and the headline population rests on extrapolation from a 16.6 percent tested subset while age and rotation stats rest on a 4.5 percent subset.
Exposure measured in the wild, exploitation unobserved
This is a measurement of real-world state rather than product uptake, and the real-world footprint is substantial: keys harvested from live public surfaces, 88 percent still authenticating on a specific date, 8,482 exposures from one platform, and 262 of 2,754 accounts with budget alerts. What is absent is the downstream half: no confirmed compromise, no victim, no attacker activity, and no statement on whether AWS quarantine policies already blunt some of these keys. Real prevalence is documented; realized harm is not.
Modestly overstated framing over solid counts
The underlying counts are conservative and clearly labeled, but the framing runs ahead of them in two ways: the aggregate 'more than 9,300 still active' figure is an extrapolation from the 16.6 percent of keys that could be re-tested and is presented as settled, and 'give full control over corporate accounts' asserts capability without any observed exploitation, provider response, or evidence that AWS has not already restricted some exposed keys. The gap is small rather than severe because the article does publish the subset denominators alongside the headline numbers.
Vendor research with direct commercial alignment
The findings originate with Truffle Security, whose commercial product is secret scanning; a study concluding that tens of thousands of leaked keys are still live and unrotated directly supports demand for that product. The article passes the vendor's counts through without noting this alignment, and closes with promotional copy for a separate commercial security report, indicating a monetized publication context. Mitigating factors are that the vendor discloses a restrictive read-only testing scope and claims owner notification, behaviors consistent with responsible disclosure rather than pure marketing.
Plausible and specific, but single-sourced and unreplicated
The internal arithmetic checks out (526 plus 242 equals the 768 full-control keys) and the findings are consistent with well-documented credential-hygiene failure modes, which supports moderate confidence in direction and rough magnitude. Confidence is held down by single-publisher sourcing, an interested originator, absent AWS and Hugging Face comment, extrapolation from partial subsets, and an unexplained exposure window that runs to a forward date.
Follow any of these and your For You feed starts watching them — no settings page required.
build
Two Actions, One Loose Policy: The Bedrock Wildcards That Widen A Least-Privilege Grant1 distinct publisher
build
A 30B model with 3B active arrives on JumpStart, aimed at the cheap middle of agent work1 distinct publisher
security
ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell3 distinct publishers
security
GitLab 19.3 puts agent runtime, inference models and secrets under one permission model1 distinct publisher