GitGuardian's 2026 State of Secrets Sprawl report reveals 28.65 million hardcoded secrets were added to public GitHub in 2025, a 34% year-over-year increase. AI service secret leaks surged 81%, with 8 of the 10 fastest-growing leak categories tied to AI services. LLM infrastructure (RAG, orchestration, vector storage) leaked 5×
Table of contents
The year software changed foreverAI is creating a new generation of leaksHardcoding secrets into MCP configsPublic leaks are only half the storyDeveloper workstations are now a prime target for secrets theft64% of valid secrets from 2022 are still active and exploitableFrom secrets sprawl to NHI governanceSort: