Leaked in 2022, Still Root in 2026
If you committed an AWS key to a public repo in 2022, here is the bad news: it probably still works. Truffle Security re-verified 10,616 publicly exposed AWS keys that had surfaced over the previous four years — in git history, Docker images, CI logs, and public datasets — and 88% of them still authenticated as of August 10, 2026. The numbers get more interesting in the corporate subset. Of the live keys, 768 give full control of a company's AWS account: 526 are root keys, 242 are IAM users carrying AdministratorAccess. Root is the scary one, because a root key can't be scoped down. In Truffle's words, it is the account, including the ability to close it. The median leaked key in the study is five years old. Five years. And most of them were never rotated. Where the keys come from matters. Truffle's scanners found 431,875 public findings resolving to 64,024 unique verified keys across 50,654 accounts, and the single largest source was not a git repository. It was Huggin...