In 2023, researchers at RWTH Aachen University in Germany published one of the largest studies of secrets hidden in container images. They analysed 337,171 images from Docker Hub and 8,076 private registries, 1,647,300 layers in total, and found that 8.5% of images contained secrets: 52,107 valid private keys and 3,158 distinct API secrets across 28,621 images. The leaked keys were not just theoretical. The researchers found 22,082 certificates relying on the exposed private keys, including 1,060 issued by public certificate authorities, and, using internet-wide scan data, 275,269 TLS and SSH hosts that used leaked private keys for authentication, including email, database, IoT messaging, SSH and Kubernetes services. Most secrets sat in images published by a single user, suggesting they were leaked by mistake. This page covers that 2023 study; a separate 2025 study is covered in our page on the Docker Hub secrets leak 2025.
Key takeaways
- RWTH Aachen researchers found secrets in 8.5% of 337,171 container images from Docker Hub and private registries.
- The images contained 52,107 valid private keys and 3,158 distinct API secrets, mostly in single-user images, suggesting accidental leaks.
- 22,082 certificates relied on the exposed keys, including 1,060 signed by public certificate authorities.
- 275,269 internet hosts used leaked private keys for authentication, including SSH servers and Kubernetes instances.
- The identity lesson: a key baked into an image is shared with everyone who pulls it, and every service that trusts that key is exposed until it is replaced.
At a glance
| Organisations | Publishers of container images on Docker Hub and 8,076 private registries; RWTH Aachen University (research) |
|---|---|
| When | Study published July 2023; reported by BleepingComputer on 16 July 2023 |
| Attacker | None known. Found by researchers at RWTH Aachen University |
| Entry point | Private keys and API secrets left inside container image layers published to registries |
| Identities abused | 52,107 private keys (TLS and SSH) and 3,158 API secrets, including cloud provider and payment service credentials |
| Impact | 275,269 internet hosts relying on leaked keys and 22,082 certificates affected; misuse not confirmed |
| Category | NHI. Incident class: exposure (secrets in public container images, no confirmed misuse) |
What happened
The paper, "Secrets Revealed in Container Images: An Internet-wide Study on Occurrence and Impact," set out to measure how often image creators ship secrets. "In this paper, we analyze 337,171 images from Docker Hub and 8,076 other private registries unveiling that 8.5% of images indeed include secrets," the authors wrote. "Specifically, we find 52,107 private keys and 3,158 leaked API secrets, both opening a large attack surface." BleepingComputer reported that the researchers validated their findings by excluding test keys, example API secrets and invalid matches, and that "Most of the exposed secrets, 95% for private keys and 90% for API secrets, resided in single-user images, indicating that they were likely unintentionally leaked."
Exposure was higher on Docker Hub, at 9.0% of images, than in private registries, at 6.3%. To see whether leaked keys were in use, the researchers checked certificates and 15 months of internet-wide scan data. "We further document that those leaked keys are used in the wild: While we discovered 1,060 certificates relying on compromised keys being issued by public certificate authorities, based on further active Internet measurements, we find 275,269 TLS and SSH hosts using leaked private keys for authentication." BleepingComputer listed hosts including MQTT and AMQP brokers, FTP and database servers, email servers, 240 SSH servers and 24 Kubernetes instances.
Most API secrets belonged to cloud providers such as AWS, with some for financial services such as Stripe, BleepingComputer reported. The researchers did not test API secrets against live services for ethical reasons, so whether they worked is unknown. There is no report of attackers using these specific secrets.
Timeline
| Date | Event |
|---|---|
| July 2023 | RWTH Aachen researchers publish their study of secrets in container images. |
| 16 July 2023 | BleepingComputer reports the findings. |
| 17 July 2023 | SOCRadar publishes a summary of the study. |
How it happened: the identity attack path
- Secrets copied into images. Keys and API secrets were included in image layers during builds.
- Images published. The images were pushed to public or reachable registries.
- Keys reused in production. Some of the same private keys secured live hosts and certificates.
- Anyone can pull. Any user of the image, or anyone scanning registries, can extract the secrets.
- Impersonation risk. Holders of a leaked private key can impersonate or decrypt traffic for hosts that use it.
Impact
- Exposed: 52,107 private keys and 3,158 API secrets in 28,621 images.
- Affected services: 275,269 hosts and 22,082 certificates relying on leaked keys, 141 CA-signed certificates still valid at the time of the study.
- Misuse: not confirmed.
What this means for NHI governance
Container images are software artefacts that travel. A private key or API token that lands in an image layer goes wherever the image goes, and deleting it in a later layer does not remove it. The RWTH study shows the result at scale: the same private keys that were published inside images were also securing hundreds of thousands of live services, so the secret and the service were both exposed.
Keys and tokens are non-human identities, and they should be injected at runtime from a secrets manager, never built into images. Image pipelines need secret scanning before push, and any key found in a published image must be treated as compromised and replaced. See our Secrets Management Guide and Kubernetes NHI Security Guide.
Recommendations
- Never build secrets into images. Inject them at runtime from a secrets manager or orchestrator. See our Secrets Management Guide.
- Scan images before pushing. Run a secret scanner in the build pipeline, and scan third-party images before deploying them.
- Replace any key found in a published image. Deleting the image does not undo copies already pulled. See the Leaked Credential Response Playbook.
- Do not reuse keys from downloaded images. Generate new keys when deploying containers based on public images. See the Cryptographic Key Management Guide.
- Use multi-stage builds and ignore files. Keep build secrets out of final layers.
Frequently asked questions
How many Docker Hub images leak secrets?
The RWTH Aachen study found that 8.5% of 337,171 images from Docker Hub and private registries contained secrets, and 9.0% of Docker Hub images specifically.
What kinds of secrets were found in container images?
52,107 private keys, used for TLS and SSH, and 3,158 API secrets, mostly for cloud providers such as AWS and some for services such as Stripe.
Is this the same as the 2025 Docker Hub leak?
No. This page covers the 2023 RWTH Aachen study. A separate 2025 study of 10,456 images is covered on our Docker Hub secrets leak 2025 page.
Related NHI Mgmt Group resources
Docker Hub Secrets Leak 2025 · iOS Apps Leaking Secrets 2025 · Secrets Management Guide · Kubernetes NHI Security Guide · Cryptographic Key Management Guide
How NHI Mgmt Group can help
Secrets in build artefacts are some of the hardest to track. We help teams scan images, move secrets to runtime injection and replace keys that have already travelled. See our NHI and AI agent security training.
References
- RWTH Aachen University: Secrets Revealed in Container Images: An Internet-wide Study on Occurrence and Impact (July 2023)
- BleepingComputer: Thousands of images on Docker Hub leak auth secrets, private keys (16 July 2023)
- SOCRadar: Docker Hub Images Expose Secrets and Private Keys, Potentially Leading to Attacks (17 July 2023)