Leaked secret · Cloud
Your AWS key
is exposed in .env?
Don't panic — but move fast. A committed or client-side AWS_SECRET_ACCESS_KEY gives anyone your AWS account, scoped to the leaked IAM user's permissions. Rotate it now, then make sure nothing else leaked.
Looks like
AWS_SECRET_ACCESS_KEY=AKIA… + secret
What an attacker can do with a leaked AWS key
⚠
Spin up expensive EC2/GPU fleets for crypto-mining on your bill
⚠
Read, download or delete your S3 buckets
⚠
Escalate privileges and pivot across your infrastructure
Fix it right now — rotate your AWS key
- 1AWS Console → IAM → Users → Security credentials → deactivate then delete the leaked access key; create a new one.
- 2Update AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY in your env and redeploy.
- 3Check CloudTrail for unfamiliar API calls and new resources, and set a billing alarm.
- 4Remove the credentials from git history.
Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.
While you're at it
Other keys people leak
Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.