Researchers Uncover 9,300 Active Leaked AWS Keys, 768 With Admin Rights
This digest was compiled by AI from multiple sources — links to the originals are below.

Truffle Security found 64,024 unique AWS key pairs across 431,875 public findings between August 2022 and August 2026. Of 10,616 pairs with complete credentials, 88% still authenticate, including 768 corporate keys with full admin rights. The researchers notified every identifiable owner.
Key Facts
- Truffle Security identified 64,024 unique AWS key pairs across 431,875 public findings between August 2022 and August 2026.
- Of 10,616 key pairs with complete credentials, 88% still authenticate, including 768 corporate AWS keys with full admin rights.
- Hugging Face was the largest single source of leaked keys, with 8,482 unique live keys across 3,394 public datasets.
- Only 9.5% of leaked keys had a budget alert configured to flag suspicious activity such as cryptocurrency mining.
- For live keys with creation dates, the median age was around five years, and the oldest was over 17 years.
Exposure Scope
Truffle Security scanned git history, Hugging Face datasets, Docker images, package registries, and CI logs. The researchers re-verified 10,616 key pairs with complete credentials and enumerated key age, attached policies, budgets, and last month's spend. No key material was published, and every identifiable owner was notified. Hugging Face accounted for 8,482 unique live keys across 3,394 public datasets, 18% of which had root privileges.
Key Age and Rotation
For live keys with creation dates, the median age was around five years, and the oldest was over 17 years. Only 13.7% of keys (398 of 2,903) had any newer key alongside the leaked one. The remaining 86% were never rotated, superseded, or cleaned up. 43% of discovered keys appeared more than once across repositories, datasets, and images.
Risk Mitigation
Truffle Security urged organizations to delete root access keys, noting that one in six leaked keys had root privileges. The report recommended sorting IAM keys by age using the AWS CLI and setting a maximum age policy. A budget alarm, even at $10, would help catch cryptocurrency mining early, as 90.5% of leaked-key accounts had no alert configured. If AWS attaches the AWSCompromisedKeyQuarantine policy to a user, it indicates the key is public.
1 source
Researchers Uncover 9,300 Active Leaked AWS Keys, 768 With Admin Rights



