Secrets Sprawl and Rotation: A Practical Vault Management Playbook
In 2025 alone, security firm GitGuardian detected 28.65 million new hardcoded secrets exposed in public GitHub commits — a 34% increase year over year and the largest single-year jump the company has recorded in five years of publishing its annual State of Secrets Sprawl report. Since 2021, that number has grown 152%, far outpacing the […]
In 2025, security firm GitGuardian recorded 28.65 million new hardcoded secrets exposed in public GitHub commits, marking a 34% increase from the previous year and the highest single-year jump in five years. This surge in "secrets sprawl" outpaces the 98% growth in GitHub's developer base during the same period, indicating that the problem is becoming increasingly urgent.
AI-assisted development is a significant contributor to this trend, with AI-generated code often leaking secrets without the usual developer caution. The financial impact of these breaches is also rising, with IBM reporting an average cost of $4.99 million for a data breach in 2026, up 12% from the previous year. Leaked credentials provide attackers with a slow-burning vulnerability, and a single hardcoded credential can remain active for months, contributing to the growing problem.
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.