The Numbers Behind the Leak
Over 9,300 leaked AWS keys are still live, according to new research from Truffle Security. That’s not a typo. The security firm scanned public sources between August 2022 and August 2026 and found 64,024 unique AWS key pairs scattered across 431,875 public findings — from git history to Hugging Face datasets, Docker images, package registries, and CI logs.
Of those, 10,616 pairs had complete credentials. The researchers re-verified every single one. The result? 88% still authenticate. And here’s the scary part: 768 of those are corporate keys with full admin rights.
What an Attacker Can Do With a Leaked Key
If a malicious actor gets hold of one of these keys, they’re not just snooping around. They could steal or delete critical cloud data, or quietly install cryptocurrency mining software to monetize the access. The report notes that only 9.5% of the leaked-key accounts had a budget alert set up — meaning the other 90.5% would likely never notice the extra charges until it’s too late.
Hugging Face: The Biggest Single Source
Hugging Face was the largest source of leaked keys, with 8,482 unique live keys found across 3,394 public datasets. A staggering 18% of those had root privileges. That’s not a minor oversight; that’s a backdoor into someone’s entire cloud infrastructure.
Key Age and Rotation: The Silent Problem
For live keys with known creation dates, the median age was around five years. The oldest? Over 17 years. That’s ancient in cloud security terms.
Rotation is rare, the report notes. Of the keys where the researchers could enumerate the user’s access keys, only 13.7% (398 of 2,903) had a newer key alongside the leaked one. The other 86% were never rotated, superseded, or cleaned up. Once a key is out there, it stays out there.
How to Protect Your AWS Environment
Truffle Security didn’t just drop the bad news and walk away. They shared practical steps to reduce the risk of leaked keys.
- Delete root access keys. Check every account, including personal ones. One in six leaked keys had root privileges.
- Sort IAM keys by age. Use
aws iam list-access-keys and set a maximum age policy to enforce rotation.
- Set a budget alarm. Even a $10 alert is better than nothing. It can catch crypto-mining early, before the bill spirals.
- Treat exposed secrets as permanently compromised. 43% of the keys discovered appeared more than once across repos, datasets, and images. If it’s out there, assume it’s burned.
- Watch for the quarantine policy. If AWS attaches
AWSCompromisedKeyQuarantine to a user, that’s AWS telling you the key is public. Act on it immediately.
The Bigger Picture: Cloud Security in 2026
This isn’t just a technical footnote. It’s a reminder that cloud security is a shared responsibility. AWS provides tools like IAM, budgets, and quarantine policies, but they only work if you use them.
The researchers also emphasized that no key material was published, and every owner they could identify is being notified. That’s good practice, but it’s not enough. If you’re a developer or a sysadmin, take a hard look at your own keys today. Check for old ones, rotate them, and set up alerts. The cost of ignoring this is far higher than a few minutes of housekeeping.
For more on related threats, check out our coverage on cloud account takeover risks and IAM key rotation best practices.