Researchers discovered 768 leaked AWS keys that are still operational, and the containment policy allows for many possibilities.
Truffle Security discovered 768 leaked AWS keys that provide complete control over corporate accounts, including 526 root keys, with 88% of the examined credentials still active. AWS implements a quarantine policy for keys identified as leaked, which still allows numerous harmful actions.
Researchers reported finding 768 compromised Amazon Web Services keys that continue to enable full access to a company’s account. Among these exposed credentials were 526 root keys, representing the highest level of privilege an AWS customer can have.
The large number of findings is due to the extensive nature of the investigation. Truffle Security gathered 431,875 AWS secrets from various sources such as repositories, git history, datasets, Docker images, and CI logs, narrowing them down to 64,024 unique keys, and tested those with complete credential access.
Most of these credentials were still functional. As of August 10, 88% of the verified keys continued to authenticate successfully, out of 10,616 tested.
The largest single source was not a traditional code host. Hugging Face was responsible for 8,482 unique key exposures, illustrating how model repositories can adopt practices from software repositories.
There is little evidence of key rotation. The median age of keys with known creation dates was around five years, and only 13.7% had a newer key issued for the same user.
Amazon responds to detected leaks by applying a quarantine policy designed to minimize fraud-related damage while maintaining, in its words, the functionality of existing resources, amid a growing issue of credential theft.
In an article for The Register, cloud economist Corey Quinn argues that this policy allows too many permissions to remain intact. Quarantined credentials can still perform certain functions in the account, execute commands on running instances, halt CloudTrail logging, and erase the audit trail completely.
One concerning example is that writing to a bucket is permitted, along with setting object locks and retention, enabling an attacker to fill storage and enforce compliance-mode retention that cannot be altered by anyone, including AWS support, without deleting the entire account.
This analysis reflects one professional's interpretation of a published policy rather than an actual incident, and it’s also a checklist that anyone can reference against Amazon’s own documentation, which is a disconcerting aspect.
For European firms, this situation presents a particular challenge. Financial institutions have been governed by the Digital Operational Resilience Act since January 2025, and TNW has reported that many of them are not adequately prepared.
A five-year-old root key in a public dataset exemplifies the third-party technology risks that these regulations require companies to identify and document. The lack of key rotation is contrary to the expectations of control that the regulation assumes should be in place.
Other articles
Researchers discovered 768 leaked AWS keys that are still operational, and the containment policy allows for many possibilities.
Researchers discovered 768 leaked AWS keys that still provided complete account access, which included 526 root keys, and 88% of the tested credentials remained valid for authentication.
