The window to stop a leaked key is the moment it leaves someone's clipboard.
The window to stop a leaked key is the moment it leaves someone's clipboard.
A leaked cloud key is supposed to be a fire drill. Someone pushes credentials to a public repo, a scanner catches it, the key gets rotated and the incident closes within the hour. Truffle Security just measured how often that story is true.
The company re-verified 10,616 AWS keys that had surfaced publicly between August 2022 and August 2026 and found that 88% still authenticate, according to its report published this month. Among the exposed corporate accounts, 768 carried full admin rights. These weren't fresh leaks caught mid-response either. Where creation dates were visible, the median key age was 1,831 days.
What did Truffle Security find in four years of leaked AWS keys?
Of the 10,616 keys tested, 9,308 were still live. Truffle Security counted 817 belonging to companies, with 526 root keys and another 242 holding AdministratorAccess on an IAM user. The report's sharpest number sits at the top of the pyramid. 130 live root keys belonged to organization management accounts, where a single compromised credential opens every member account in the org.
Rotation, the industry's standard answer to a leaked credential, barely registers in the data. Of the keys where the researchers could enumerate a user's access keys, only 13.7% had any newer key alongside the leaked one. AWS itself had flagged 929 active users with its compromised-key quarantine policy. The keys still authenticated, since quarantine limits abuse rather than killing the credential. Nobody followed up. Cybernews, which covered the research, noted that Hugging Face was the largest single source of exposed keys and that the leaked keys racked up $420,631 in AWS spending in July alone.
Why doesn't cleanup happen after a key leaks?
From the outside, a five-year-old live key looks like negligence. From the inside, it's a backlog. A key created in 2020 for an experiment has no owner by 2026. Nobody rotates a credential nobody remembers creating, attached to an account nobody can name, in a spreadsheet nobody maintains. The quarantine finding makes the point without any help. The cloud provider raised its hand, applied a policy and waited. The owners never came.
Security leaders know this pattern from their own alert queues. When the volume of things demanding manual follow-up outruns the team, follow-up becomes theoretical. The failure isn't detection. Detection worked four years ago, when these keys first hit public scanners. What never arrived was the human hour each key needed after that.
How do you stop a key at the moment it leaks?
Faster rotation would help. Preventing the leak helps more, because everything downstream of the paste is exactly the cleanup work this report proves never gets done.
Every one of these keys left through a human moment. A push to a public repo. An upload to a Hugging Face space. A config file dropped into a ticket or a chatbot to debug an error. Those moments happen on endpoints and in browsers, which is where MIND's real-time prevention operates. The platform's multi-layer classification recognizes code and configuration files by content and context, so a live credential doesn't need a perfect regex or a manual label to be caught on its way out. And because the controls are adaptive, the response can fit the moment. A speed bump that asks a developer to look twice at a paste, with a block reserved for the genuinely risky move. MIND is minding the gap between a credential leaving a clipboard and a four-year cleanup that never starts.
“I was blown away by the fact that I could actually, in real time, stop someone from copying, pasting sensitive information from Slack into ChatGPT.”
Al Faiella
Senior Director of Security Engineering, ThoughtSpot
Truffle Security closes its report with advice to delete every exposed root key. Do that. The longer fix is making sure the next key never needs the advice. See what MIND catches in your environment. Deployment takes minutes and prevention can be on the same day. Let's mind what matters.










