Skip to content
Hacker News front page

Truffle Security scanned 7.6 PB of HuggingFace training data and found 221k live secrets

Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets

Truffle Security scanned every public dataset on Hugging Face—7.6 PB across 187 million files—and found 221,303 live, unique credentials in 6,003 datasets. One high-impact secret gave access to 393 GB of PII covering an estimated 3.7% of the global population. Supply-chain risk is concrete: 349 live GitHub PATs, including 223 with full repo write, 130 that can rewrite CI workflows, and 112 with admin:org; plus 318 Docker Hub tokens that can push images. One repo-scoped token belonged to the founder of a widely used MCP registry whose repos have over 178k GitHub stars. On the infrastructure side, 8,557 GCP service-account keys spanned 3,811 projects, 51.7 TB of S3 buckets had public access blocked but leaked keys, and 8,594 database logins were still live—the largest single MongoDB cluster exposed 617.7 GB. HuggingFace’s CTO contributed native storage-bucket scanning to TruffleHog after disclosure. The post withholds specific company and project names but mentions healthcare, payment apps, a US defense contractor, and a Brazilian federal agency.

Why it matters: Truffle Security scanned every public HuggingFace dataset—7.6 PB, 187M files—and found 221k live credentials, including one key accessing PII for ~3.7% of the global population. It's a rare large-scale empirical study in AI supply-chain security with concrete, wide-reaching nu...

Read the original ↗Export Markdown