29 Million Secrets Leaked on GitHub Last Year. AI Coding Tools Made It Worse.
GitGuardian published the fifth edition of its State of Secrets Sprawl report on March 27. It's the largest study of credential exposure on public GitHub, and this year's edition lands a finding th...

Source: DEV Community
GitGuardian published the fifth edition of its State of Secrets Sprawl report on March 27. It's the largest study of credential exposure on public GitHub, and this year's edition lands a finding that the AI agent ecosystem needs to sit with. AI-assisted commits leak secrets at roughly twice the rate of human-only commits. And 24,008 unique secrets were found specifically in MCP configuration files. Those aren't estimates. They're counts. The Numbers The headline stats from the report: 28.65 million new hardcoded secrets detected in public GitHub commits in 2025. A 34% year-over-year increase and the largest single-year jump GitGuardian has recorded. AI-assisted commits had a 3.2% secret-leak rate, versus a 1.5% baseline across all public GitHub commits. That's roughly 2x the baseline. AI-service credentials (API keys for LLM providers, embedding services, AI platforms) increased 81% year-over-year, reaching 1,275,105 detected leaks. 24,008 unique secrets were found in MCP configuration