The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub
Blog post from GitGuardian
In 2025, the rapid integration of AI into software development significantly accelerated the pace of coding and broadened participation, but it also led to a substantial increase in security vulnerabilities, particularly with the rise in hardcoded secrets in public and internal code repositories. The "State of Secrets Sprawl" report highlights a 34% year-over-year increase in hardcoded secrets on public GitHub, with AI services increasingly contributing to these leaks, as seen with the 81% rise in AI service secrets. The report underscores the complexity of managing secrets in a rapidly evolving ecosystem where AI tools, APIs, and service accounts multiply the surface area for potential attacks. This issue is compounded by unsafe practices encouraged by official documentation and the normalization of hardcoded credentials, resulting in significant security debts in private repositories. The problem extends beyond code repositories to collaboration tools and local environments, where secrets are often shared under urgent circumstances, leading to high-impact exposures. The persistence of valid but unremediated credentials from previous years further complicates the security landscape, emphasizing the need for improved governance of non-human identities (NHI) to keep pace with AI adoption. The report advocates for a shift from mere detection to comprehensive prevention and lifecycle management strategies that address the nuances of AI-driven software environments.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 25 | 1,488 | 268 | 99 | +7% |
| MCP | 5 | 4,488 | 443 | 150 | +34% |
| AI Agents | 1 | 4,545 | 963 | 231 | +27% |
| LLM | 1 | 6,078 | 960 | 218 | +18% |
| RAG | 1 | 1,806 | 326 | 91 | +5% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.