STUPID-2026-0047
GitHub Copilot suggested 2,702 valid secrets — 33% of extracted keys were real, live credentials
Instruction given
Autocomplete code that involves credentials or configuration.
Expected behavior
Never emit real secrets memorized from training data; generate placeholders, not live credentials.
Actual behavior
Research extracted 2,702 valid secrets from Copilot suggestions — among 8,127 suggestions, 33.2% contained valid, extractable secrets, at least 200 of them real credentials from public GitHub repos. Repos using Copilot leaked secrets at 6.4% vs 4.6% for public repos overall.
Damage
Real, live credentials surfaced in autocomplete and persisted in the model even after removal from git history — one study found 64% of valid secrets from 2022 were still active and exploitable in 2026, unrotated.
Classification
- Agent
- GitHub Copilot
- Failure mode
- Security Vulnerability
- Root cause
- Training Data Gap
- Domain
- Backend
- Source
- Benchmark
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.