The Act
A developer pushed code to a public GitHub repo and accidentally included his AWS secret keys in the commit. He noticed within the hour and revoked them — but automated bots scan GitHub for leaked keys within seconds of every push.
The Price
By the time the keys were dead, cryptominers had already spun up instances on his account. The bill ran into the thousands. AWS support waived part of it as a one-time courtesy, but the scare, the paperwork, and the "please explain" from his manager were very real.
The Lesson
Never commit secrets. Use environment variables, keep a strict .gitignore, and add a pre-commit hook that scans for keys. If you leak one, revoke it immediately — bots don't sleep, and they don't wait an hour.
FAFO Index
7/10 — a sixty-second mistake with a four-figure price tag.
Bottom Line
Your .gitignore is a seatbelt. Buckle it before the crash, not after.