August 1, 2026
Leaked keys, hurt feelings
Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets
They searched the AI internet for leaked passwords, and the comments instantly went feral
TLDR: Researchers scanned a huge public AI data library and found more than 221,000 working secrets, including keys that could unlock private data and update software people use. Commenters split between panic, jokes, and roasting the article’s overdramatic writing instead of the security nightmare itself.
A massive security sweep just tore through 7.6 petabytes of public AI training data on Hugging Face—basically one of the biggest places where developers store data used to teach artificial intelligence—and found 221,303 live secrets still working in the wild. We’re talking passwords, cloud account keys, code-publishing access, and even one especially scary find linked to personal data affecting an estimated 3.7% of the world. Yes, that is exactly the kind of sentence that makes readers sit upright and whisper, “oh no.”
But the real popcorn moment? The community reaction. One camp was horrified by the scale and went full doom-meme mode, with the perfect deadpan response: “This is fine. All of this is fine. :’)” Another group got instantly distracted by the article’s dramatic tone, dragging the writing itself instead of the leak apocalypse. One commenter said they “can’t stand the Claude writing,” roasting lines like they were reviewing a movie trailer, not a security report. And then came the practical skeptics: if the internet is full of leaked secrets, why focus on Hugging Face at all? One user bluntly asked whether it wouldn’t be easier to just crawl the whole web.
Even the numbers sparked snark. While the report tried to make its giant data pile sound relatable, commenters were not having it, with one basically saying: please just give us 7.6 PB, not “Empire State Building heights worth of DVDs.” In other words, the leak was huge, the risks were real, and the comments somehow turned a terrifying scan into a roast session.
Key Points
- •The scan of all public Hugging Face datasets covered 7.6 petabytes and 187 million files, finding 221,303 live unique credentials in 6,003 datasets.
- •The article says one exposed secret provided access to 393 GB of PII affecting an estimated 3.7% of the global population.
- •Researchers found supply-chain-sensitive credentials including 349 live GitHub personal access tokens and 318 Docker Hub tokens with push capabilities.
- •The article reports 8,557 live Google service-account keys across 3,811 GCP projects, including Firebase admin keys, an Owner-role key, and a Kubernetes cluster-admin credential.
- •The findings were disclosed to Hugging Face before publication, and CTO Julien Chaumond is credited with contributing storage-bucket scanning support to TruffleHog.