Truffle Security found 768 leaked AWS keys granting full control of corporate accounts, including 526 root keys, with 88% of tested credentials still active. AWS applies a quarantine policy to keys it detects as leaked, which still permits a long list of damaging actions.
Researchers have found 768 leaked Amazon Web Services keys that still give full control of a company’s account. Among the exposed credentials were 526 root keys, the most privileged thing an AWS customer possesses.
The scale of the search explains the number. Truffle Security collected 431,875 AWS secrets from repositories, git history, datasets, Docker images and CI logs, reduced them to 64,024 unique keys, and tested those where complete credentials were available.
Most of them worked. As of 10 August, 88% of the verified keys still authenticated, out of 10,616 tested.
The largest single source was not a code host in the traditional sense. Hugging Face accounted for 8,482 unique key exposures, which is what happens when model repositories inherit the habits of software ones.






