GitGuardian Uncovers 20 Million Leaked Credentials on GitHub
While we’re all busy marveling at how fast AI can generate code, no one is talking about the terrifying amount of sensitive data it’s leaving behind in plain text. GitGuardian CMO Carole Wingwist and Principal Developer Advocate Dwayne McDaniel join Techstrong TV to discuss their jaw-dropping 2025 State of Secrets Sprawl report, revealing that over 20 million secrets were leaked on public GitHub in a single year—a massive 34% spike driven directly by AI coding assistants. With the rise of autonomous agents like OpenClaw specifically engineered to hunt for these credentials, organizations are facing a critical reckoning where they must secure not just their human developers, but the very AI tools building their future.
Transcript
Hey, everyone. Welcome back here to Techstrong TV. I've got two people to introduce you to today.
It's always a pleasure when we have two people on. Let me first int- introduce you to Carole Winquist. Carole is, the CMO at GitGuardian.
And Carole, welcome to Techstrong TV. It's great to have you making your first appearance here on Techstrong TV. It's great to have you.
Thank you for inviting me, Alan. Yes, so I'm, as you said, the CMO of GitGuardian. I've been with the company five years, so I've seen the growth from, pre-Series B company to now a post-Series C, 'cause we just announced it.
So thank you for having me. Yes, and congratulations on that. You know what, Carole, be- let me introduce Dwayne, then I'm gonna come back to you a little bit, though.
Um, also joining us is Dwayne McDaniel. Dwayne, welcome to Techstrong TV. This is your first time on, since we have two first-timers.
Welcome. How are you? I'm doing great.
Thanks very much for having me. Uh, yes, I'm Dwayne McDaniel. I'm Principal Developer Advocate at GitGuardian.
I've been here about three and a half years. Uh, and I absolutely love engaging with the community. Uh, if you go to our blog or our YouTube, you'll see my face and my name over there a, a lot.
And I love keeping up with the trends out there, and I'm very excited to talk to you about our annual report today. Excellent. Before we do, though, we've got some other stuff to talk about.
Carole, you say you're at GitGuardian now about five years. Give people a sense of, you, you know, what'd you do before that? What'd you do, you know, six years ago?
What did... Give us a sense of your path, your journey to- Um- GitGuardian ... my journey is, being a CMO in, B2B enterprise SaaS software for too many years.
More than you want to admit. Yeah, exactly. And, before that, I was working in, business process management.
Uh, and I came to cybersecurity with GitGuardian, and it has been, an awesome learning, curve, I should say, and I love it. Uh, the product, is really, amazing and brings value to the community and to make a, a safer world. So it's a bit, yeah, quirky sometimes, but yes, we do our, our best to help.
So I'm- You know, but, but that's... And I've been in cybersecurity myself for 25, 30 years, and people sometimes lose sight that that's why a lot of peop- a lot of us are in here is, it's, there is a bit of a feel good. It's frustrating because progress is slow.
And you know the thing about security, right? When nothing happens, you did your job. But that being said, knowing that you're, you're on the good side, on the right side, is, is a good thing.
Um, I'd love to talk to you about your feelings around business process and SaaS companies with AI, but we'll save that for another interview. We got stuff to talk about today, but... And welcome.
Dwayne, let's hear, you're here about three and a half years, you said, at GitGuardian. Let's hear a little bit of your career arc. Oh, believe it or not, Carole and I used to work for the same business process management- Really?
years ago. Oh, okay. Uh, but we, but not at the same time.
We didn't actually meet until I started- Oh, really? working here at GitGuardian. And, just, like Carole, this is my first foray into properly working in the security realm.
I'd been talking about security off and on for the last decade of my life in developer relations across platforms and Git tooling. Uh, in fact, I first mentioned GitGuardian, after their first report because I started including them in a talk about Git hooks and keeping secrets out of your source code when you commit it. Uh, and now I do that professionally.
So I'm very, very proud to do that. Good for you. That's great.
What a great story. So you guys were both at the same company at different times. Yes.
They didn't know each other, came here and met. Yeah, exactly. Sounds like a romantic comedy or something.
A rom-com. But anyway, so look, you both have been excited to come to GitGuardian. GitGuardian is a...
I, like I said, I've been in security a long time. GitGuardian's a company that we've, you know, had seen the name, a lot of us. I bet a lot of our audience, being security people, have seen, you know, heard of GitGuardian.
But I don't, you know, I always wonder, I always worry that people have heard a name doesn't mean they know the company, right? So Carole, as the CMO, I'm sure you've spent a lot of time in the exercise of, you know, who we are, what's our brand mean, what, what is, what is GitGuardian? So I'm gonna ask you, if you don't mind, to carry this one and s- give people in our audience, who is GitGuardian, right?
What, what does GitGuardian do? And, and can I brag a little bit, Alan? Well, go.
Uh, that's my role as a CMO, right? So I, I, I should say, I, I can say we are the global leader of secret security and non-human identity security. We've been doing this since 2017, and if you ask us about secrets, I think we know, we know it all, right?
We, we, we've done it. We've taken the challenge to make sure company, can basically know where their secrets are. The one that are, you know, well managed in vaults, but have maybe some problematics with their hygiene being long-lived or, over-permissioned, but also all the secrets that sprawl everywhere because they are hard-coded in code.
Everybody, I think, knows that that's happening, but also in other tools like Jira, Confluence, Slack. And, and this is a big problem, as, as most of your audience should know, I think. And this morning, again, there was a leak, with the SalesLoft, hack-And Telus has been breached because you know, the, the attackers found some credentials when they breached SailLoft, and now they're using it to breach into Telus and move laterally and find more secrets and enumerate secrets all over the place and just hack again another company.
So I think show-- seeing all these breached where secrets are the initial, element that help hackers enter but also move laterally, that's why we, we are, I think, bringing a real solution to the market. And, and not just because we help detect everything, right? Because you can detect, but what do you do, right, if you, if you don't have action plans?
So, we, we like to say that basically, GitGuardian really help closes the, the all these incident at scale. So we, we, we sell into very large company, but we also offer the solution for individual developers or, or company below twenty-five for free because that's our good Samaritan, approach to the market. But for large and complex companies, we, we bring a solution that not only enumerates and, and shows the secrets, but also help remediate and put into action so that at some point there is a real management of, this problematics of secrets within the company.
Excellent. Very good. Dwayne, I'm gonna give you...
Carole was pretty, you know, covered it from A to Z, but anything you wanna add that, you know, in your role you're out here talking to people a lot, right? Evangelizing, listening. A lot of people think evangelists talk a lot, but a good evangelist listens a lot, right?
What are you hearing? What are people saying to you about GitGuardian? Well, pe- one, people really appreciate the fact that we're free for open source projects and for individual developers.
It's an enterprise-grade tool that anybody can use. Uh, the biggest benefit, I think, to the community is that Good Samaritan program, that Carole mentioned. Uh, so we scan every new commit that hits GitHub public, every single one.
Um, there have never been more, last year, in fact, m- not to preview the, the report numbers, but a forty-three percent increase in commits scanned last year. That's just that more, much more happening on GitHub. And if we find a secret, we email the committer right then and there.
It's a fully automated system. We've sent out more emails last year than we ever have before, to, again, to kinda tease the numbers coming up. Um, but that is the biggest benefit and why most people know us.
They've gotten an email, and you see it out there on social media. People say, "Just got an email from GitGuardian. " Some people get angry that, you know, they leaked the secret in the first place.
Not at us, but, just the fact that it exists. And, and that's how most people first find out about us. And then when they realize, hey, that same powerful engine that we use to detect secrets, not just the ones with the prefixes, not just the ones that match a, a regex, but contextually does this high-entropy string allow access to something?
We can hook that up to literally anything with text, be it your developer machine, be it your production environments. Uh, and now because we integrate with the vault systems and the identity managers, literally anything inside your ecosystem. And once you have that true visibility into the access mechanisms, backfilling the rest of the information and finding out what state it's in, giving you a way to actually tell if you are governing your secrets at scale, that-that's what we do, and that's what people know us for out there.
Excellent. Thanks, Dwayne. That was great too.
All right. com is the website, and that's probably the best and easiest way to kinda on-ramp onto Git, whether you're looking as it, at it from a net or onto GitGuardian, excuse me. Whether you're looking at it as an enterprise potential customer or even just, as you say, Dwayne, an individual or open source project who, who wants to take advantage of, of the free offering here.
Um, Dwayne, you also made reference to this survey or annual survey report, which recently came out. Uh, since you mentioned it, I'm gonna ask you to kick it off. W- Tell us about it.
So, that same engine that reports on if you leaked a secret or not, what we obviously are collecting that data, and we've been doing this now, this is our fifth annual report. So we look over the course of a calendar year, what has happened on GitHub. Uh, this year, I'll just say the giant number, we found twenty million six hundred and forty-nine thousand secrets added to GitHub just in the year twenty-twenty-five.
That's not cumulative. That's not the total that's on GitHub. It's much more than that.
Uh, this is a thirty-four percent increase year over year. Last year, re-revised numbers from last year, is down, twenty-one million added in twenty-twenty-four, eighteen million in twenty-twenty-three. Uh, go back to the twenty-twenty-one numbers using the exact same methodology, exact same scans, 'cause, you know, public GitHub and our records of it, eleven million.
Uh, so overall, we've seen a hundred and fifty-two percent growth of secret leaks. Now, to put that in perspective, that's not all just, hey, this is all new devs. Uh, active devs in that same span has increased ninety-eight percent on GitHub.
Hmm. It's-- Last year was the biggest increase ever on GitHub's platform of new developers, amount of code we're pushing, amount of everything we're pushing. But that's, like, just part of the story.
Um, what we're pushing is changing. The, the complexity of the code, the complexity of all of these non-human identities, these workloads that need to work together and authenticate back and forth to make up our apps, to make up our pipelines, to make up-Literally all the ecosystem in tech, it's just never been this complex, and there's never been more people doing it at the same time. It's kind of this perfect storm of because we're using AI, just first time it's come up this conversation, we're using AI so much, and AI is trained so much on existing code.
I would say it's, it's built on the, back of code on the internet, and I don't know if you've ever seen the internet, but it's kinda terrible. We did it kind of wrong. " And we think that's a good chunk of why we're seeing that increase.
And you see people like me pushing code, right? So you have now in my team, in Mark's team- Well, now you, you just hit it on the head. I...
So yes, it's, it's frustrating, I think, to see that... L- l- let me back up. Let me give you the good news.
There is a ever-growing minority of users out there who are getting savvy about secrets, right, through GitGuardian's efforts and, and so forth. But at the same time, we are being overwhelmed. We're seeing this in AppSec with the amount of vulnerabilities or potential vulnerabilities being found by using AI scanning.
We're seeing it in places like GitHub and other places where we went from a universe of maybe, maybe forty to fifty million people who code in the whole world. I think that's about... " 'Cause the whole concept of who, who is coding and what is a, what does being a coder or a developer actually mean has changed.
Carole, when you and I are developers, and I, I was busy this morning on, you know-- Don't even ask. But, it amazes me because I never considered myself anything more than some hacker, and, and not even a hacker. I'm a business guy.
But you can ma- Anybody can create anything today. So but the repercussions of that is, Dwayne, exactly what you're describing. We're seeing the amount of code being generated exponentially go up, and with that not, you know, the amount of secrets going up, the amount of, I'm afraid to say it, but probably the amount of vulnerabilities and insecurities out there are also multiplying.
'Cause as much as we look at... At enterprise levels, I guess we're scanning. We're using tools like GitGuardian for secrets.
We're using AppSec tools to, to look at our code. But when you, when you ten-x the amount of people developing code- Yeah ... this is what you're dealing.
I mean, I, I don't know another, you know-- As much as I'd like to sugarcoat it, there's no sugarcoating it here. So- And, and we're not going to stop it, right? So we- Oh, yeah.
What are you gonna lay down in front of the railroad tracks and hope the tra- Exactly. So- That train's not stopping ... we just need to help.
Yeah. And all- We need to help the enterprise. Yeah, we need to help, and we need...
And not only the... I mean, helping the enterprise is great. It keeps the lights on, right?
But even helping these open source projects, even helping the army of, let's call them, civilian developers, right, who are d- now finding themselves, you know... So not from the IT department even, the people in the HR department, in the marketing department, who are making their own apps all of a sudden because they can. They need help too.
I mean, it's almost, you know, it's the shadow AI thing where the IT team who may have GitGuardian available doesn't even know that Carole and her people just made a quick little app for some little project they're doing, and they're running it, you know, on some Mac Mini somewhere or something like a lot of people are doing. It's a crazy time. It's a crazy time we're living in.
So Dwayne, you, you mentioned some great metrics here. I always like to ask people when we, when we get into talking about reports, what wasn't on your bingo card? What, what didn't you see coming?
I, I intellectually kind of thought we were gonna see a giant massive spike in AI services and whatnot, but what actually rolled out even shocked me. Uh, the... It's not just that we're developing code with AI, we're never building, building more stuff with AI, the AI infrastructure.
Uh, as y- you know, with when you're building AI, the cost of the tokens is just one part of your ecosystem. It's just one part of the total equation. Um, there's-- I had never...
Before we started putting this report together, I had heard the name Open Router, but I am not an AI developer. I am not building, with multi models and, like, bouncing around models trying to find what's the best model for this use case. Uh, but Open Router, we saw a forty-eight x increase in number of leaks from twenty twenty-four to twenty twenty-five data.
Um- Really? It... Forty-eight x.
It's the fastest-growing detector I think we've ever seen, I'm pretty sure that we've ever seen across any report. Um, and then you look down that list, and the next fastest-growing was DeepSeek. Next after that was Brave Search API, which is the go-to default MCP server for so many projects out there.
So we started seeing this pattern of it's not just we're building more code. What we're building has literally shifted. Now-The good and bad news of that is it's not bringing a whole brand new branch of vulnerabilities.
These are the same vulnerabilities. The OWASP Top 10 is still the OWASP T- Top 10. All the other security reports you read of, like, what we're doing with AI, it's still misconfiguration.
It's still leaked credentials. It's still broken access. It's still all the other problems- It's more of it ...
vulnerabilities. Yeah. We're, we're- A lot more of it ...
we're making these mistakes a lot faster now, and there's just more people making them. And we're building- Yeah ... making it with different technology, slightly different technology.
So let me be the optimist. Look, we're, we're seeing a lot more of it 'cause AI is, is developing a lot more of it, right? This is AI generated.
But we're also... Part of it may be also that we're using AI to discover it, and our ability to scan and find these things with AI is, is, it's not part of the problem 'cause it's not a problem. It's never a problem finding more vulnerabilities or more, you know, potential bugs or security, it, you know, ways.
But it- it's overwhelmed. It's overwhelming. I, I wrote an article on this, like, earlier this week.
It seems like two weeks ago already. But it's overwhelming, right? So, like, the developer, professional developers now, it's not so much that they're actually coding anymore.
They're, they're managing. The- it's about governance, right? Governance of, of, of all this code, you know, securing all this code is overwhelming our abilities, our resources.
We, we just c- you know, you can't, you can't 10X the amount of code that you're putting in without 10X-ing the governance or, you know, be really- But it- ... 5X-ing the govern- without, you know, some big increase. And, and we leverage this, I think...
I mean, yes, y- you're talking about, we are talking about the risk that AI brings, but AI is also on the side of the defenders, right? We, we use it to improve our products. Uh, at GitGuardian, for example, we use machine learning since quite a long time to basically, fine-tune the model so that it detects better, but also help on severity scoring, on contextualization, on analyzing the code so that the AppSec team, they, they can make decision, on severity based on actual facts and not random just, checkers or just a, a little bit of info.
And we know there are fewer, far fewer AppSec people than developers, and we need to help them. We need to help them figure out the 10 secrets that really, really, really are the hottest, most dangerous one first, and then they can go to the 10 next and the 10 next, right? So, and some of them, some of the, the, the secrets can be just closed because, I don't know, they, they, they're not valid anymore, and they are on a test environment, so let's just, kill the incident.
So yeah, that's how we use AI on our side. Um, of course, we, we, we, we leverage this, all the time because we have to go fast too to, to help, and, and not only, helping on, you know, the environment, the software development life cycle, but we are now moving also towards the, the laptop of the developer because, you probably heard of the Shyulood and, and all these new, attacks we've had, in the past six months where the, actually the, the endpoint, the, the laptop is the target because hackers know there a, a realm of, of secrets, and they can harvest, and they can then, then use them for further attacks. So we, we are now protecting this endpoint too, because we are a strong believer then, you know, the developer, the AppSec team, the IMT need to work together to actually fix the problem.
Yeah. No, it's forcing us. It's for- look, you need AI to beat AI at some level, right?
Exactly. Yeah. But it's also, it, it's like the snake that swallowed the rat, right?
This rat has to work its way through from the developer to the, to the tester, to the AppSec person, to the deployment, to the SRE. We're gonna see this disruption wave, if you will, just, you know, work its way through the, the whole process, and it may not be a bad thing. You know?
It, it, it could work. I, I definitely see a reckoning happening out there. Uh, and one other fact to kind of put this in perspective, as a part of our platform, we, we do validation.
We do, non-intrusive calls to see if the thing works. And we took a subset of our findings from 2022. We did this in the 2025 report, so 2024 data.
Think the 2022 numbers are like about 11,000, and we said, "Hey, these were valid in 2022. " And 70% roughly came back as still valid. Wow.
And we did that again this year, same data set, 64% come back valid. Uh, secrets that we found valid across 2025, end of the year, 77% stayed valid. Like, w- we're talking about pre-AI boom, or recurrent, the AI development boom.
So this is a known problem. This points to that larger issue of governance. But now with attacks shifting the way they are, and if there's a credential, it will be abused, and we just have to assume that now.
It used to be if it gets pushed, we're gonna assume it's gonna be abused. If it's in plain text, in something someone could break into, it's gonna be abused. It's forcing this reckoning of governance that, okay, we're going to have to deal with this now at scale, and identity in general at scale in a way that we've never really had to before.
It's really forcing the issue, which I think is a good thing ultimately. Well, yeah. I mean, no one wants to do things because there's a gun to your head, right?
But, but sometimes it takes that sense of urgency to get people to, to act. Right. There's no both ways.
Hey, guys, we're, we're probably over time here. For people who wanna maybe get a copy of the report and see some of these, like, mind-blowing numbers for themselves, what, what's the best, what's the best place to go? com, and then you'll find the report advertised on the homepage or, you know, it's there.
Excellent. 2020 Sy- S- State of Secrets Sprawl. And it's sprawling it is.
Sprawling it is. Yes. Carole, Dwayne, thank you so much for coming here on Techstrong TV with us today and talking secrets a little bit.
Um, continued success. Keep up... Look, as I s- I...
We were talking off camera. You know the thing about security, right, is when nothing happens, you're doing your job. When it comes to secrets, security, and stuff like that, so many of us take for granted that we're, we're secure or we haven't, you know...
Or maybe we're just the zebra who didn't get eaten by the lion that day, right? Different zebra. But, you know, the work that you guys do and at GitGuardian is good work.
A- as you said, Carole, that's the reason, one of the reasons you're there, right? It's, it's, it's being one of the good guys. Keep it up, and we appreciate it, and have a great day.
Thank you, Alan. You bet. Thank you.
All right. We're gonna take a break here on Techstrong TV. We'll be back in just a moment.