Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Secrets in Docker Hub Images: What the RWTH…
Breach analysis Incident: 16 Jul 2023

Secrets in Docker Hub Images: What the RWTH Aachen Study Found in 337,171 Container Images

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
On this page

In 2023, researchers at RWTH Aachen University in Germany published one of the largest studies of secrets hidden in container images. They analysed 337,171 images from Docker Hub and 8,076 private registries, 1,647,300 layers in total, and found that 8.5% of images contained secrets: 52,107 valid private keys and 3,158 distinct API secrets across 28,621 images. The leaked keys were not just theoretical. The researchers found 22,082 certificates relying on the exposed private keys, including 1,060 issued by public certificate authorities, and, using internet-wide scan data, 275,269 TLS and SSH hosts that used leaked private keys for authentication, including email, database, IoT messaging, SSH and Kubernetes services. Most secrets sat in images published by a single user, suggesting they were leaked by mistake. This page covers that 2023 study; a separate 2025 study is covered in our page on the Docker Hub secrets leak 2025.

Key takeaways

  • RWTH Aachen researchers found secrets in 8.5% of 337,171 container images from Docker Hub and private registries.
  • The images contained 52,107 valid private keys and 3,158 distinct API secrets, mostly in single-user images, suggesting accidental leaks.
  • 22,082 certificates relied on the exposed keys, including 1,060 signed by public certificate authorities.
  • 275,269 internet hosts used leaked private keys for authentication, including SSH servers and Kubernetes instances.
  • The identity lesson: a key baked into an image is shared with everyone who pulls it, and every service that trusts that key is exposed until it is replaced.

At a glance

OrganisationsPublishers of container images on Docker Hub and 8,076 private registries; RWTH Aachen University (research)
WhenStudy published July 2023; reported by BleepingComputer on 16 July 2023
AttackerNone known. Found by researchers at RWTH Aachen University
Entry pointPrivate keys and API secrets left inside container image layers published to registries
Identities abused52,107 private keys (TLS and SSH) and 3,158 API secrets, including cloud provider and payment service credentials
Impact275,269 internet hosts relying on leaked keys and 22,082 certificates affected; misuse not confirmed
CategoryNHI. Incident class: exposure (secrets in public container images, no confirmed misuse)

What happened

The paper, "Secrets Revealed in Container Images: An Internet-wide Study on Occurrence and Impact," set out to measure how often image creators ship secrets. "In this paper, we analyze 337,171 images from Docker Hub and 8,076 other private registries unveiling that 8.5% of images indeed include secrets," the authors wrote. "Specifically, we find 52,107 private keys and 3,158 leaked API secrets, both opening a large attack surface." BleepingComputer reported that the researchers validated their findings by excluding test keys, example API secrets and invalid matches, and that "Most of the exposed secrets, 95% for private keys and 90% for API secrets, resided in single-user images, indicating that they were likely unintentionally leaked."

Exposure was higher on Docker Hub, at 9.0% of images, than in private registries, at 6.3%. To see whether leaked keys were in use, the researchers checked certificates and 15 months of internet-wide scan data. "We further document that those leaked keys are used in the wild: While we discovered 1,060 certificates relying on compromised keys being issued by public certificate authorities, based on further active Internet measurements, we find 275,269 TLS and SSH hosts using leaked private keys for authentication." BleepingComputer listed hosts including MQTT and AMQP brokers, FTP and database servers, email servers, 240 SSH servers and 24 Kubernetes instances.

Most API secrets belonged to cloud providers such as AWS, with some for financial services such as Stripe, BleepingComputer reported. The researchers did not test API secrets against live services for ethical reasons, so whether they worked is unknown. There is no report of attackers using these specific secrets.

Timeline

DateEvent
July 2023RWTH Aachen researchers publish their study of secrets in container images.
16 July 2023BleepingComputer reports the findings.
17 July 2023SOCRadar publishes a summary of the study.

How it happened: the identity attack path

  1. Secrets copied into images. Keys and API secrets were included in image layers during builds.
  2. Images published. The images were pushed to public or reachable registries.
  3. Keys reused in production. Some of the same private keys secured live hosts and certificates.
  4. Anyone can pull. Any user of the image, or anyone scanning registries, can extract the secrets.
  5. Impersonation risk. Holders of a leaked private key can impersonate or decrypt traffic for hosts that use it.

Impact

  • Exposed: 52,107 private keys and 3,158 API secrets in 28,621 images.
  • Affected services: 275,269 hosts and 22,082 certificates relying on leaked keys, 141 CA-signed certificates still valid at the time of the study.
  • Misuse: not confirmed.

What this means for NHI governance

Container images are software artefacts that travel. A private key or API token that lands in an image layer goes wherever the image goes, and deleting it in a later layer does not remove it. The RWTH study shows the result at scale: the same private keys that were published inside images were also securing hundreds of thousands of live services, so the secret and the service were both exposed.

Keys and tokens are non-human identities, and they should be injected at runtime from a secrets manager, never built into images. Image pipelines need secret scanning before push, and any key found in a published image must be treated as compromised and replaced. See our Secrets Management Guide and Kubernetes NHI Security Guide.

Recommendations

  • Never build secrets into images. Inject them at runtime from a secrets manager or orchestrator. See our Secrets Management Guide.
  • Scan images before pushing. Run a secret scanner in the build pipeline, and scan third-party images before deploying them.
  • Replace any key found in a published image. Deleting the image does not undo copies already pulled. See the Leaked Credential Response Playbook.
  • Do not reuse keys from downloaded images. Generate new keys when deploying containers based on public images. See the Cryptographic Key Management Guide.
  • Use multi-stage builds and ignore files. Keep build secrets out of final layers.

Frequently asked questions

How many Docker Hub images leak secrets?

The RWTH Aachen study found that 8.5% of 337,171 images from Docker Hub and private registries contained secrets, and 9.0% of Docker Hub images specifically.

What kinds of secrets were found in container images?

52,107 private keys, used for TLS and SSH, and 3,158 API secrets, mostly for cloud providers such as AWS and some for services such as Stripe.

Is this the same as the 2025 Docker Hub leak?

No. This page covers the 2023 RWTH Aachen study. A separate 2025 study of 10,456 images is covered on our Docker Hub secrets leak 2025 page.

Docker Hub Secrets Leak 2025 · iOS Apps Leaking Secrets 2025 · Secrets Management Guide · Kubernetes NHI Security Guide · Cryptographic Key Management Guide

How NHI Mgmt Group can help

Secrets in build artefacts are some of the hardest to track. We help teams scan images, move secrets to runtime injection and replace keys that have already travelled. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on Non-Human Identity and Agentic AI security, every week.

    Bonus 33% off our NHI Foundation Level Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org