FEATUREDHacker News Frontpage· rssEN18:21 · 08·01
→Truffle Security scanned 7.6 PB of HuggingFace training data and found 221k live secrets
Truffle Security scanned every public dataset on Hugging Face—7.6 PB across 187 million files—and found 221,303 live, unique credentials in 6,003 datasets. One high-impact secret gave access to 393 GB of PII covering an estimated 3.7% of the global population. Supply-chain risk is concrete: 349 live GitHub PATs, including 223 with full repo write, 130 that can rewrite CI workflows, and 112 with admin:org; plus 318 Docker Hub tokens that can push images. One repo-scoped token belonged to the founder of a widely used MCP registry whose repos have over 178k GitHub stars. On the infrastructure side, 8,557 GCP service-account keys spanned 3,811 projects, 51.7 TB of S3 buckets had public access blocked but leaked keys, and 8,594 database logins were still live—the largest single MongoDB cluster exposed 617.7 GB. HuggingFace’s CTO contributed native storage-bucket scanning to TruffleHog after disclosure. The post withholds specific company and project names but mentions healthcare, payment apps, a US defense contractor, and a Brazilian federal agency.
#Truffle Security#HuggingFace#Julien Chaumond
why featured
Featured · importance 78 · hook + knowledge + resonance
editor take
221k live secrets found in HuggingFace datasets; one key unlocked PII for ~3.7% of the global population.
sharp
The numbers here are hard to ignore: Truffle Security scanned 7.6 PB of public HuggingFace datasets and found 221,303 live, unique credentials across 6,003 datasets. One high-impact secret unlocked 393 GB of PII covering an estimated 3.7% of the global population—the post says a dedicated follow-up is coming, so details are thin for now.
The supply-chain risk is worse than I expected. 349 live GitHub PATs, including 223 with full repo write, 130 that can rewrite CI workflows, and 112 with admin:org. One repo-scoped token belonged to the founder of a widely used MCP registry whose repos have over 178k GitHub stars—someone could push code directly into tooling that a huge number of developers depend on. 318 Docker Hub tokens can push images; npm and PyPI came up clean.
Infrastructure exposure is just as bad: 8,557 GCP service-account keys across 3,811 projects, 51.7 TB of S3 buckets with public access blocked but keys leaked, and 8,594 live database logins—the largest single MongoDB cluster exposed 617.7 GB.
HuggingFace's CTO contributed native storage-bucket scanning to TruffleHog after disclosure, which is a decent response. The post withholds specific company and project names but mentions healthcare, payment apps, a US defense contractor, and a Brazilian federal agency. I'd discount this slightly since Truffle Security sells secret-scanning products and this is marketing content, but the 7.6 PB scan scope and verification method (metadata-only checks, no row reads) make the numbers credible. The write-capable supply-chain tokens are the real thing to worry about—they're not 'potentially abusable,' they're ready to exploit the moment someone finds them.
HKR breakdown
hook ✓knowledge ✓resonance ✓