“We took the 10,616 pairs with complete credentials and re-verified them, then enumerated what each key can tell us about its account: key age, attached policies, budgets, and last month's spend.”
Truffle Security's scan: scale and active exposure
Security vendor Truffle Security reported that over 9,300 leaked AWS keys that surfaced between August 2022 and August 2026 remain active, including hundreds with full administrative rights. The company’s scanners identified 64,024 unique AWS key pairs across 431,875 public findings — locations such as git history, Hugging Face datasets, Docker images, package registries and CI logs.
From that dataset, Truffle said it isolated 10,616 pairs with complete credentials and re-verified them. Of those 10,616, 88% still authenticate. The findings include 768 corporate AWS keys with full admin rights. Truffle also reported that only 9.5% of keys had a budget alert set up to flag anomalous spend, leaving 90.5% without that protection.
Truffle emphasized handling and notification practices in its disclosure: “No key material is published, and every owner we could identify is being notified.”
Hugging Face datasets emerged as the largest single source
Among public repositories and datasets, Hugging Face was the single largest source of leaked keys identified by Truffle Security. The vendor reported 8,482 unique live keys discovered across 3,394 public datasets on Hugging Face; 18% of those keys were found to have root privileges.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleKey age, rotation, and quarantine signals
For the live keys where creation dates were available, Truffle found a median age of roughly five years and identified at least one key that was more than 17 years old. The company described rotation as uncommon: of the keys where it could enumerate a user’s access keys, only 13.7% — 398 of 2,903 — had any newer key alongside the leaked one. “The other 86% were never rotated, superseded, or cleaned up,” Truffle reported.
The report also urged attention to AWS’ quarantine tagging: if AWS attaches the label “AWSCompromisedKeyQuarantine” to a user, Truffle said, it is indicating the key is public.
Who can be hurt and how: admin and root privileges
Truffle’s findings raise straightforward operational risks. The report notes that an AWS account takeover could allow malicious actors to steal or delete cloud data or covertly install cryptocurrency-mining software to monetize access. The presence of hundreds of corporate keys with full admin rights and a substantial share of root-privileged keys among Hugging Face discoveries underscores the potential impact of this exposure.
Recommended mitigations Truffle published
- Delete root access keys, checking every account, including personal ones. The report claimed one in six leaked keys had root privileges.
- Sort IAM keys by age using “aws iam list-access-keys” plus a maximum age policy.
- Set a budget alarm to catch crypto-mining early. Truffle noted that even a $10 alert would be better than nothing, given that 90.5% of leaked-key accounts have no alert set up.
- Treat exposed secrets as permanently compromised: 43% of those discovered by the researchers appeared more than once across repos, datasets, and images.
- Watch for the quarantine policy: If AWS attaches “AWSCompromisedKeyQuarantine” to a user, it is saying that the key is public.
What this means for technologists, enterprises, and the public
- Technologists and security teams should prioritize detection and cleanup: the report’s recommendations — delete root keys, list-access-keys to sort by age and enforce rotation, and set low-value budget alerts — are concrete steps tied to the specific exposures Truffle uncovered.
- Affected enterprises and procurement leaders will need to account for persistent credential exposure in public artifacts (git history, datasets, images and registries) when assessing vendor and supplier risk; Truffle’s finding that 43% of secrets reappear across assets highlights the persistence of this failure mode.
- End users and developers should check personal and project accounts for lingering root or long-lived keys and treat any discovered public secret as permanently compromised, per Truffle’s guidance.
Truffle Security’s inventory-style disclosure leaves a clear, quantifiable trail: thousands of live keys, hundreds with admin or root privileges, long key ages, and low levels of rotation or budget alerting. The company’s dual message — that it re-verified credentials and is notifying owners, and that organizations should delete, rotate and monitor keys — sets a practical, measurable checklist for anyone responsible for AWS accounts.
Source: Infosecurity Magazine — Researchers Uncover Thousands of Leaked AWS Keys




