<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/researchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-poss-nhccuafhw" -->

---
title: Researchers found 768 leaked AWS keys that still work,...
description: Truffle Security scanned repositories, git history, datasets, Docker images and CI logs and found 768 leaked AWS keys still granting full account control,...
canonical: https://daily.dev/posts/researchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-poss-nhccuafhw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Researchers found 768 leaked AWS keys that still work, and the containment policy leaves plenty possible | daily.dev
og:description: Truffle Security scanned repositories, git history, datasets, Docker images and CI logs and found 768 leaked AWS keys still granting full account control,...
og:url: https://daily.dev/posts/researchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-poss-nhccuafhw
og:image: https://api.daily.dev/og/posts/nHCCuAfhw.png
og:image:alt: Researchers found 768 leaked AWS keys that still work, and the containment policy leaves plenty possible
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Researchers found 768 leaked AWS keys that still work, and the containment policy leaves plenty possible

**[The Next Web](https://daily.dev/sources/tnw)** · 3 min read · 0 upvotes · 0 comments

## Summary

Truffle Security scanned repositories, git history, datasets, Docker images and CI logs and found 768 leaked AWS keys still granting full account control, including 526 root keys. Out of 10,616 verified credentials tested as of August 10, 88% still authenticated. Hugging Face was the largest single leak source with 8,482 unique key exposures, and the median leaked key was about five years old with only 13.7% rotated. Cloud economist Corey Quinn argues AWS's quarantine policy for detected leaked keys still permits dangerous actions: assuming other roles, running commands on instances, stopping CloudTrail logging, deleting audit trails, and writing to S3 buckets with compliance-mode object lock that can't be shortened even by AWS support without deleting the whole account. The piece ties this to Europe's DORA regulation, which requires financial firms to document third-party technology risk like this.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/researchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-possible>

## Questions this post answers

### How many leaked AWS keys were found still working and how many were root keys?

Truffle Security identified 768 leaked AWS keys that still grant full control of a company's account, including 526 root keys, the most privileged credential type AWS offers. Testing 10,616 verified credentials as of August 10, 88% still authenticated. The keys were gathered from 431,875 AWS secrets scraped across repositories, git history, datasets, Docker images, and CI logs.

_Teams auditing AWS credential exposure follow root-cause security research like this on daily.dev._

### What can an attacker still do with an AWS key that AWS has quarantined after detecting a leak?

AWS's quarantine policy for leaked keys limits fraud-related actions but still permits assuming other roles in the account, running commands on already-running instances, stopping CloudTrail logging, and deleting the audit trail entirely. Attackers can also write to S3 buckets and apply object lock with compliance-mode retention, which cannot be shortened by anyone, including AWS support, short of deleting the entire account.

_Engineers hardening AWS incident response track gaps like these in cloud security policy on daily.dev._

### Where do most leaked AWS keys come from besides GitHub?

Hugging Face was the single largest source of leaked AWS keys in a large-scale scan, accounting for 8,482 unique key exposures, more than traditional code hosting platforms. This reflects model repositories inheriting the same credential-hygiene habits as software repositories. The median leaked key with a known creation date was about five years old, and only 13.7% had a newer key issued to the same user.

_Developers securing ML pipelines and model repos watch findings like this on daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#aws](https://daily.dev/tags/aws), [#secrets-management](https://daily.dev/tags/secrets-management)

[View this post on daily.dev](https://daily.dev/posts/researchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-poss-nhccuafhw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Researchers found 768 leaked AWS keys that still work, and the containment policy leaves plenty possible","url":"https://daily.dev/posts/researchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-poss-nhccuafhw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/researchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-poss-nhccuafhw"},"datePublished":"2026-08-22T10:45:02.865Z","dateModified":"2026-08-22T10:46:16.428Z","description":"Truffle Security scanned repositories, git history, datasets, Docker images and CI logs and found 768 leaked AWS keys still granting full account control,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/978a355e07dadbf134734d94f9a1c967?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/978a355e07dadbf134734d94f9a1c967?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Next Web","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Next Web","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tnw","url":"https://daily.dev/sources/tnw"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/researchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-poss-nhccuafhw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,aws,secrets-management","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Next Web","item":"https://daily.dev/sources/tnw"},{"@type":"ListItem","position":3,"name":"Researchers found 768 leaked AWS keys that still work, and the containment policy leaves plenty possible"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/researchers-found-768-leaked-aws-keys-that-still-work-and-the-containment-policy-leaves-plenty-poss-nhccuafhw#faq","mainEntity":[{"@type":"Question","name":"How many leaked AWS keys were found still working and how many were root keys?","acceptedAnswer":{"@type":"Answer","text":"Truffle Security identified 768 leaked AWS keys that still grant full control of a company's account, including 526 root keys, the most privileged credential type AWS offers. Testing 10,616 verified credentials as of August 10, 88% still authenticated. The keys were gathered from 431,875 AWS secrets scraped across repositories, git history, datasets, Docker images, and CI logs. Teams auditing AWS credential exposure follow root-cause security research like this on daily.dev."}},{"@type":"Question","name":"What can an attacker still do with an AWS key that AWS has quarantined after detecting a leak?","acceptedAnswer":{"@type":"Answer","text":"AWS's quarantine policy for leaked keys limits fraud-related actions but still permits assuming other roles in the account, running commands on already-running instances, stopping CloudTrail logging, and deleting the audit trail entirely. Attackers can also write to S3 buckets and apply object lock with compliance-mode retention, which cannot be shortened by anyone, including AWS support, short of deleting the entire account. Engineers hardening AWS incident response track gaps like these in cloud security policy on daily.dev."}},{"@type":"Question","name":"Where do most leaked AWS keys come from besides GitHub?","acceptedAnswer":{"@type":"Answer","text":"Hugging Face was the single largest source of leaked AWS keys in a large-scale scan, accounting for 8,482 unique key exposures, more than traditional code hosting platforms. This reflects model repositories inheriting the same credential-hygiene habits as software repositories. The median leaked key with a known creation date was about five years old, and only 13.7% had a newer key issued to the same user. Developers securing ML pipelines and model repos watch findings like this on daily.dev."}}]}
```

