GitGuardian's 2026 State of Secrets Sprawl report reveals 28.65 million hardcoded secrets were added to public GitHub in 2025, a 34% year-over-year increase. AI service secret leaks surged 81%, with 8 of the 10 fastest-growing leak categories tied to AI services. LLM infrastructure (RAG, orchestration, vector storage) leaked 5× faster than core model providers. Claude Code-assisted commits showed a 3.2% secret-leak rate vs. a 1.5% baseline. MCP configuration files exposed 24,008 unique secrets, partly because official documentation encourages unsafe hardcoding patterns. Internal repos are 6× more likely than public ones to contain secrets, and 28% of incidents originate outside code repositories in tools like Slack and Jira. Analysis of 6,943 compromised developer machines found nearly 295,000 secret occurrences, with 59% of compromised machines being CI/CD runners. Critically, 64% of secrets confirmed valid in 2022 remain exploitable today, highlighting a severe remediation gap. The report calls for NHI governance frameworks covering ownership, access scope, and lifecycle management.

6m read timeFrom blog.gitguardian.com
Post cover image
Table of contents
The year software changed foreverAI is creating a new generation of leaksHardcoding secrets into MCP configsPublic leaks are only half the storyDeveloper workstations are now a prime target for secrets theft64% of valid secrets from 2022 are still active and exploitableFrom secrets sprawl to NHI governance
286 Impressions