Major security oversight: 88% of leaked AWS keys still work
In July alone, leaked active keys racked up over $420,631 in AWS spending.

Photo by Kabir Jhangiani/NurPhoto via Getty Images
- Truffle Security found 88% of 10,616 leaked AWS keys still worked after surfacing publicly since August 2022.
- Among exposed corporate accounts, 768 had full admin rights, including 526 root keys and 242 AdministratorAccess users.
- Many keys were old and unrotated: 86% had no newer replacement key alongside the leaked credential.
- Leaked keys created serious financial risk, with checked accounts spending $420,631 in July alone.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Following cyber incidents, companies are quick to assure users that all credentials are rotated. Researchers checked over 10,000 AWS keys that leaked since 2022 August and the results are shocking: 88% still authenticate.
People change their toothbrushes more often than companies rotate a leaked AWS key. For most, the answer is never.
Researchers at Truffle Security, an open-source security software company, tested thousands of keys leaked over 4 years, and what they found is hard to believe.
“We re-verified 10,616 leaked AWS keys on August 10th, 2026. They surfaced publicly between August 2022 and August 2026. 88% still authenticate,” the report reads.
Truffle Security only tested the key pairs with complete credentials.
Of the 10,616 audited keys, 9,308 were still live, and 817 belonged to companies. 768 of those exposed corporate accounts had full admin rights, giving complete control over a company's AWS account: 526 are root keys, and another 242 hold AdministratorAccess on an IAM user.
“At the far end sit 130 live root keys on organization management accounts, the account that controls every member account in the org. One compromised management root exposes every account in the org at once,” the researchers warned.
Hugging Face, an open-source AI platform and community, is the largest source of exposed keys.
Most of the still active exposed keys are over 5 years old. Three out of ten keys allowed viewing of creation dates, and the median was 1,831 days. The oldest key was created 17.4 years ago. Only 2 dozen keys were from the last 30 days.
“Rotation is the rarer event. Of the keys where we could enumerate the user's access keys, only 13.7% (398 of 2,903) have any newer key alongside the leaked one. The other 86% were never rotated, superseded, or cleaned up,” the report reads.
AWS itself was active in restricting exposed keys: 929 of the 7,590 active IAM users, or 12%, carried the AWSCompromisedKeyQuarantine policy. The keys still authenticate – nobody acted on it.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Only 262 accounts out of 2754 that had budgets exposed had budget alerts – the median ceiling was configured at $8, a free tier guardrail level.
While the typical key opens an abandoned experiment that costs nothing to the owner, some were very sensitive production keys: 9 keys spent over $10,000 last month, 41 keys spent $1,000-$10,000.
The total spending on the leaked keys, as far as the researcher could check, was $420,631 in July alone.
Truffle Security warns that all the exposed root access keys should be deleted.
“Check every account you own, including the personal one from 2019.”