Secrets · 24 September 2026 · 5 min read

We published a test key to a public repository and timed what happened next. The first attempt to use it came in under a minute.

Written by Hannah Lindqvist · Detection engineer

Developers at desks with code on their monitors

Bots read every public push. We know because we pushed a decoy key and watched.

The timeline

  • 0:38: first attempt to use the key
  • 2:10: attempts from eleven networks
  • 4:00: the point at which a revoke still costs you nothing

What to do

Scan before the push, not after. And make revoking a key one click, because the person who finds it at 2 am will not have the runbook open.

What the attempts looked like

None of them were clever. Each one listed what the key could reach and moved on.

1. List the buckets

2. List the users

3. Try to create a new key

The attacker does not need to be fast. The bot already was.

A key that is revoked in four minutes has been tried, and has failed.

End of post

Secrets · 24 September 2026 · 5 min read

We published a test key to a public repository and timed what happened next. The first attempt to use it came in under a minute.

Written by Hannah Lindqvist · Detection engineer

Developers at desks with code on their monitors

Bots read every public push. We know because we pushed a decoy key and watched.

The timeline

  • 0:38: first attempt to use the key
  • 2:10: attempts from eleven networks
  • 4:00: the point at which a revoke still costs you nothing

What to do

Scan before the push, not after. And make revoking a key one click, because the person who finds it at 2 am will not have the runbook open.

What the attempts looked like

None of them were clever. Each one listed what the key could reach and moved on.

1. List the buckets

2. List the users

3. Try to create a new key

The attacker does not need to be fast. The bot already was.

A key that is revoked in four minutes has been tried, and has failed.

End of post

Secrets · 24 September 2026 · 5 min read

We published a test key to a public repository and timed what happened next. The first attempt to use it came in under a minute.

Written by Hannah Lindqvist · Detection engineer

Developers at desks with code on their monitors

Bots read every public push. We know because we pushed a decoy key and watched.

The timeline

  • 0:38: first attempt to use the key
  • 2:10: attempts from eleven networks
  • 4:00: the point at which a revoke still costs you nothing

What to do

Scan before the push, not after. And make revoking a key one click, because the person who finds it at 2 am will not have the runbook open.

What the attempts looked like

None of them were clever. Each one listed what the key could reach and moved on.

1. List the buckets

2. List the users

3. Try to create a new key

The attacker does not need to be fast. The bot already was.

A key that is revoked in four minutes has been tried, and has failed.

End of post

Start here

Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.

Nothing is scanned until you connect a source. No card needed.

We will sweep

  • Identity providerNot connected
  • Cloud accountsNot connected
  • DevicesNot connected
  • Code repositoriesNot connected

Start here

Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.

Nothing is scanned until you connect a source. No card needed.

We will sweep

  • Identity providerNot connected
  • Cloud accountsNot connected
  • DevicesNot connected
  • Code repositoriesNot connected

Start here

Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.

Nothing is scanned until you connect a source. No card needed.

We will sweep

  • Identity providerNot connected
  • Cloud accountsNot connected
  • DevicesNot connected
  • Code repositoriesNot connected
Palisade

Palisade watches every identity, device and key your company runs on, finds what is exposed and closes it before it turns into a breach.

Book a demo
© 2026 Palisade Security Ltd. All rights reserved. All systems securedPrivacyTermsCookies
Palisade

Palisade watches every identity, device and key your company runs on, finds what is exposed and closes it before it turns into a breach.

Book a demo
© 2026 Palisade Security Ltd. All rights reserved. All systems securedPrivacyTermsCookies
Palisade

Palisade watches every identity, device and key your company runs on, finds what is exposed and closes it before it turns into a breach.

Book a demo
© 2026 Palisade Security Ltd. All rights reserved. All systems securedPrivacyTermsCookies

Create a free website with Framer, the website builder loved by startups, designers and agencies.