Product1 distinct publisher2 min readUpdated
A sweep of public code, datasets and CI logs found 768 AWS keys with full account control. The containment policy AWS applies to detected leaks still permits deleting the audit trail.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The policy Amazon applies when it spots a leaked key is meant to limit fraud-related damage without, in its own phrasing, impacting existing resources [7]. That second clause does most of the work. Writing in The Register, the cloud economist Corey Quinn reads the published policy and lists what a quarantined credential can still do: assume other roles in the account, run commands on running instances, stop CloudTrail logging, and delete the audit trail outright [8]. Quinn also notes that writing to a bucket is permitted, as is setting object lock and retention, so an attacker can fill storage and apply compliance-mode retention that nobody can shorten, AWS support included, without deleting the whole account [9].
That is one practitioner's reading of a document rather than a demonstrated attack [10], and it deserves that label. It is also checkable line by line against Amazon's own documentation, which makes it harder to dismiss than a proof of concept nobody else can reproduce.
Now the arithmetic of the sweep itself. Truffle Security could only fully test 10,616 of its 64,024 unique keys, or 16.6 percent of the corpus [2]. Inside that slice, 9,342 credentials still authenticated [1], and roughly 68 percent of the full-control finds were root keys rather than lesser IAM users [3]. The 768 figure is therefore a floor drawn from a sixth of the sample, not a census.
The rotation numbers are what make the quarantine policy load-bearing in the first place. Only 13.7 percent of users with an exposed key ever issued a newer one [6], which leaves 86.3 percent of that population with no successor credential at all [4]. A key with no replacement is a key that was never meant to be revoked, because revoking it breaks something.
The source mix is the part that should reallocate somebody's scanning budget. Hugging Face alone produced 8,482 unique key exposures, 13.2 percent of every distinct key in the study and the largest single origin [5][5]. TNW's framing is that model repositories have inherited the habits of software ones; the corpus also included Docker images and CI logs [4], which are not where credential hygiene programmes usually look.
All of which points at the same dependency. Quarantine only fires on keys Amazon detects as leaked [7]. The control that works without detection is rotation, and by Truffle Security's own count it is not happening.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Truffle Security found 768 leaked AWS keys granting full control of corporate accounts.
Among the exposed credentials were 526 root keys, the most privileged credential an AWS customer holds.
As of 10 August, 88% of the verified keys still authenticated, out of 10,616 tested.
Truffle Security collected 431,875 AWS secrets from repositories, git history, datasets, Docker images and CI logs, and reduced them to 64,024 unique keys, testing those where complete credentials were available.
Hugging Face was the largest single source, accounting for 8,482 unique key exposures; TNW frames this as model repositories inheriting the habits of software repositories.
The median key with a known creation date was about five years old, and only 13.7% had a newer key issued to the same user.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Quantified but single-sourced and unverified
The numbers are specific, internally consistent (88% of 10,616 ≈ 9,342; 526/768 ≈ 68%; 8,482/64,024 ≈ 13.2%) and attributed to a named research sweep. But the cluster contains exactly one publisher, no primary Truffle Security report, no AWS quarantine policy document, no AWS comment, and the most alarming assertions are relayed from a third-party column the article itself calls an undemonstrated reading.
Real, dated field measurement of live exposure
This is not a proposal or a launch but observed reality: tens of thousands of credentials harvested from live repositories, datasets, images and CI logs, with a dated authentication test on 10 August establishing that most still work, and a rotation statistic showing the exposure persists for years. What is missing is any measure of downstream uptake or response — no notification counts, no remediation rate, no incident attributed to these keys.
Mildly overstated by framing, restrained in text
The article is unusually self-limiting — it explicitly labels Quinn's permission list as an unproven reading of policy — which pulls the gap toward zero. It rises above zero because the cluster framing pairs 'AWS quarantines leaked keys' with '9,342 of them still work', a derived figure drawn from the whole tested pool rather than from quarantined or full-control keys, and because the most dramatic scenario (irreversible compliance-mode retention) is presented without verification, AWS response, or any observed exploitation.
Vendor research plus commentator amplification
The findings originate with Truffle Security, a security firm whose subject is secret scanning, published as a scale-of-exposure sweep — a format that both informs and advertises the capability. The interpretive escalation comes from a named cloud commentator writing in The Register, whose reading is adversarial to AWS and unrebutted here because no AWS comment was obtained. TNW adds a self-referential hook to its own prior DORA readiness reporting. These are visible, attributed interests, not hidden ones, so the reading is moderate rather than high.
Moderate on counts, low on the containment thesis
Confidence is split. The exposure statistics are specific, dated, internally consistent and clearly attributed, so the existence of a large live-credential problem is fairly reliable even from one publisher. The story's distinctive claim — that AWS's quarantine still permits audit-trail destruction and irreversible retention — rests on a single unverified practitioner reading with no vendor response, which caps overall confidence near the midpoint.
security
Leaked AWS keys keep working: 526 root, 242 admin, and a rotation rate of 13.7 percent2 distinct publishers
product
Cinemas, classrooms and ICE: smart glasses now need a venue-policy contingency1 distinct publisher
build
Two Actions, One Loose Policy: The Bedrock Wildcards That Widen A Least-Privilege Grant1 distinct publisher
product
OpenAI prices its own guardrails: 20% more compute, plus a two-week training pause1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.