
GitGuardian Research Reveals 150,000 Certificates Linked to Leaked Private Keys from GitHub and Docker Hub
Gaitan Ferry and Guillaume Valadon from GitGuardian's Cyber Security Research team presented their research on leaked private keys and certificate transparency at SSTIC 2026. Their company specializes in detecting secrets in open and closed sources, and they had accumulated approximately 1 million private keys found on GitHub and Docker Hub with no way to determine ownership or usage. They partnered with Google's certificate transparency team to access historical certificate data, which totaled approximately 12 petabytes, with individual logs like Google's Argon containing 4 billion certificates in 2025 alone. By matching private keys to certificates through public key identifiers, they identified 150,000 certificates corresponding to 40,000 private keys, with 2,622 certificates still valid in September 2025. They contacted 600 organizations with 4,300 emails but received only 54 responses, including just 10% response rate from national CERTs across 19 governmental entities in multiple countries. Their analysis revealed that 20% of compromised keys had been leaked more than 2 years prior, with some exposed for over 5 years while certificates continued to be renewed with the same compromised keys. They recommend automatically renewing private keys with each certificate renewal, which tools like Certbot already do by default, especially as certificate validity periods decrease toward 47 days by 2029.