FILE No.EN-03 · ONLINE

The AWS Key Committed to GitHub

ARCHIVED
2026-10-01 · source: rewritten from a developer postmortem thread

The Act

A developer pushed code to a public GitHub repo and accidentally included his AWS secret keys in the commit. He noticed within the hour and revoked them — but automated bots scan GitHub for leaked keys within seconds of every push.

The Price

By the time the keys were dead, cryptominers had already spun up instances on his account. The bill ran into the thousands. AWS support waived part of it as a one-time courtesy, but the scare, the paperwork, and the "please explain" from his manager were very real.

The Lesson

Never commit secrets. Use environment variables, keep a strict .gitignore, and add a pre-commit hook that scans for keys. If you leak one, revoke it immediately — bots don't sleep, and they don't wait an hour.

FAFO Index

7/10 — a sixty-second mistake with a four-figure price tag.

Bottom Line

Your .gitignore is a seatbelt. Buckle it before the crash, not after.

Seen something like this?

Report it anonymously — submissions are rewritten and anonymized before publishing.

Report incident

MORE FAFO STORIES

The $390,000 'Antivirus Refund

phone scam mistakes to avoid

The 'Dream Job' That Asked for a Deposit

online job scam mistakes to avoid

One Password to Lose Them All

password reuse mistakes to avoid