Half a million working passwords and API keys are sitting in a dataset built to teach AI models how to write code. Truffle Security scanned The Stack v3, a snapshot of 224,553,295 public GitHub repositories assembled for training large language models, and found 543,699 unique credentials that still authenticated when the team tested them on 27 and 28 July 2026.
That matters because a training corpus is copied, mirrored and downloaded far more widely than any single repository. A key that leaked into one config file years ago now sits in a public dataset anyone can pull.
Years old and still answering
The median live credential had been sitting in a public default branch for 784 days, according to Truffle Security's research. The oldest, a set of database credentials in a web server config last touched in June 2009, still worked. A quarter of the haul is older than four years, and the team found 2,636 live credentials in files last modified before 2015. Truffle says it is not naming the repositories because the credentials in them still work.
The biggest live categories were Google Cloud service account credentials (69,041), MongoDB connection strings (51,067) and Google API keys (33,343). The team also counted 31,374 live Gemini API keys, billable credentials attached to Google's AI model endpoints, with a median leak date of February 2025. Other live finds included 11,465 Postgres connection strings, 9,189 SendGrid keys and 6,819 AWS access keys.
Blocking at the door, nobody revoking inside
GitHub turned push protection on by default for public repositories on 29 February 2024, so a push carrying a recognised secret is blocked unless the developer overrides it. Truffle's measurements suggest that worked where it applies: the leak rate for the credential types GitHub blocks fell 53 percent across the twelve months either side of the rollout, against 7 percent for the types it ignores. Even so, just under 200,000 of the live credentials were pushed after the default changed.
The bigger gap is coverage. Connection strings, private keys and Google API keys are not blocked by default, and together they make up 51.8 percent of everything still live. What really decides whether a leaked key stays dangerous, Truffle argues, is whether the issuing provider automatically revokes it. Of 101,886 committed npm tokens, one still worked. Of 12,985 Postgres connection strings, 11,465 did.
The finding echoes recent work on how freely cloud and AI keys circulate, including Wiz's study of the secrets infostealers take, and the exposure of thousands of companies' keys in the LiteLLM supply chain attack.
Rotate first, then check whether you are in The Stack
Truffle's advice is to treat any committed credential as burned the moment it lands, rotate it before cleaning up history, scan your own repository history rather than trusting push-time blocks (anything committed before February 2024 was never in scope), prefer credentials that expire on their own, and check whether your provider takes part in a revocation programme. Italy's CERT-AGID adds a practical first step: use Hugging Face's Am I in The Stack? lookup to see whether your GitHub user or organisation's code is in the dataset, then scan those repositories for verified, still-working secrets with Truffle Security's open-source scanner.
Deleting a file does not take a key back out of a dataset that has already been copied. Only revoking it does.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.