In October 2021, an anonymous user posted a 125GB torrent on 4chan containing what they said was the whole of Twitch: the streaming platform's source code with its commit history, internal tools, proprietary SDKs, an unreleased Amazon Game Studios project and three years of creator payout figures. Twitch confirmed the breach and said data "was exposed to the internet due to an error in a Twitch server configuration change that was subsequently accessed by a malicious third party." It reset every streamer's stream key as a precaution and said passwords and payment card numbers were not exposed. The less visible risk was inside the code. When GitGuardian scanned the roughly 6,000 leaked Git repositories, it found nearly 6,600 secrets, including 194 AWS keys, 69 Twilio keys, 68 Google API keys and hundreds of database connection strings. Whether any were still valid, or were used, has not been published.
Key takeaways
- Twitch says the breach came from an error in a server configuration change that let an unauthorised third party access data; it has not published more detail.
- The leak included about 6,000 internal Git repositories with commit history, according to GitGuardian, plus creator payout data that streamers confirmed matched their own records.
- GitGuardian found nearly 6,600 secret candidates in the repositories, including 194 AWS keys and 14 GitHub OAuth keys, and more than 1,100 repositories contained at least one.
- Twitch reset all stream keys and said its bcrypt-hashed login credentials and full card numbers were not accessed.
- The identity lesson: stolen source code is a credential leak, because secrets committed years ago stay in Git history.
At a glance
| Organisation | Twitch (owned by Amazon) |
|---|---|
| When | Leak published on 4chan around 5 to 6 October 2021; Twitch confirmed the breach on 6 October 2021 |
| Attacker | Unknown; an anonymous 4chan poster published the data |
| Entry point | An error in a Twitch server configuration change that exposed data to the internet, according to Twitch |
| Identities abused | Secrets committed to Twitch source code (AWS, Twilio, Google API, Stripe and GitHub OAuth keys and database connection strings) were exposed; streamer stream keys were reset as a precaution |
| Impact | Source code for Twitch and related properties, internal tools and creator payout data leaked publicly; nearly 6,600 embedded secrets exposed; no confirmed use of those secrets has been reported |
| Category | NHI. Incident class: confirmed NHI breach (secrets exposed in stolen source code) |
What happened
On 5 and 6 October 2021, a post on 4chan linked to a 125GB archive labelled "part one". According to Bitdefender and TechCrunch, it contained the entirety of twitch.tv with commit history, Twitch's mobile, desktop and console clients, proprietary SDKs and internal AWS services, other Twitch properties such as IGDB and CurseForge, an unreleased Amazon Game Studios Steam competitor and Twitch's internal red team tools. It also held creator payout reports. "I looked at a line from June 2019 and literally 100% match to the information showing on my analytics on my dashboard," one streamer said, as quoted by TechCrunch.
Twitch confirmed the breach on 6 October. Its first update said: "We have learned that some data was exposed to the internet due to an error in a Twitch server configuration change that was subsequently accessed by a malicious third party." On 7 October it reset all stream keys "out of an abundance of caution". On 15 October it said passwords had not been exposed, that systems storing login credentials hashed with bcrypt were not accessed, and that "the exposed data primarily contained documents from Twitch's source code repository, as well as a subset of creator payout data."
Two months later, GitGuardian published an analysis of the leaked repositories. It found "nearly 6,600 secrets inside the Twitch Git repositories", including 194 AWS keys, 69 Twilio keys, 68 Google API keys, hundreds of database connection strings, 14 GitHub OAuth keys and four Stripe keys. More than 1,100 of the roughly 6,000 repositories contained at least one secret candidate, counting their history. GitGuardian deliberately did not test the keys, so it could not say how many were valid at the time. It also noted an AWS key in a configuration file committed on the day of the breach, and 14 AWS keys in a repository named Backend/CloudServices.
GitGuardian's point was that the leak of code was only the visible part of the risk. An attacker who kept quiet could have worked through those credentials before anyone knew the code had been taken. Twitch has not said which secrets it rotated beyond stream keys.
Timeline
| Date | Event |
|---|---|
| 5 October 2021 | A 4chan post links to a 125GB archive of Twitch data, according to TechCrunch. |
| 6 October 2021 | Twitch confirms the breach and blames an error in a server configuration change. |
| 7 October 2021 | Twitch resets all stream keys as a precaution. |
| 15 October 2021 | Twitch says passwords, login credential stores and full card numbers were not accessed and that exposed data was mainly source code and some payout data. |
| 22 December 2021 | GitGuardian publishes its analysis of nearly 6,600 secrets in the leaked repositories. |
How it happened: the identity attack path
- Misconfiguration. A server configuration change exposed internal data to the internet, according to Twitch.
- Bulk access to repositories. An unauthorised party copied about 6,000 Git repositories, including commit history, and payout data.
- Public release. The data was posted to 4chan, putting it in anyone's hands.
- Secrets exposed with the code. Thousands of credentials committed to the repositories over the years, for cloud, messaging, payment and code hosting services, became readable by anyone with the archive.
- Precautionary rotation. Twitch reset stream keys; it has not described wider rotation of the secrets found in the code.
Impact
- Confirmed: leak of Twitch source code, internal tools, SDKs and creator payout data. Twitch said customer impact was "minimal" and contacted affected users directly.
- Exposed credentials: nearly 6,600 secret candidates in the code, according to GitGuardian; their validity and any use are unknown.
- Not affected, according to Twitch: passwords, bcrypt-hashed login credential stores, full card numbers and bank details.
What this means for NHI governance
This breach is usually remembered for streamer earnings. For identity teams, the lasting lesson is the credentials. Nearly 6,600 secrets across more than 1,100 repositories means secrets were a normal part of how Twitch's code was written, and GitGuardian said the volume was typical of what it sees in new customers. Every one of those keys belonged to a service or application, not a person, and most had no expiry.
When source code leaks, every secret in its history must be treated as compromised, even ones deleted years ago. That is only practical if secrets are kept out of code in the first place and injected from a managed store, and if the organisation knows which service each key belongs to so it can rotate them quickly. Our Secrets Management Guide and Leaked Credential Response Playbook cover both.
Recommendations
- Assume leaked code means leaked secrets. After any source code exposure, scan the full history and rotate every live credential found. See the Leaked Credential Response Playbook.
- Keep secrets out of repositories. Use a secrets manager and short-lived credentials so code never needs to carry a key. See our Secrets Management Guide.
- Scan every commit before it lands. Pre-commit and CI secret scanning stops new secrets entering history.
- Map each key to an owner and a service. Fast rotation depends on knowing what a key does and who can change it. See the NHI Ownership Guide.
- Review configuration changes that affect exposure. Changes to network, storage or repository access should be checked for public exposure before and after deployment.
Frequently asked questions
How was Twitch hacked in 2021?
Twitch says an error in a server configuration change exposed data to the internet, where a malicious third party accessed it. The data, including source code and creator payouts, was then posted on 4chan.
Were Twitch passwords leaked?
No. Twitch said passwords were not exposed and that systems storing bcrypt-hashed login credentials were not accessed. It reset all stream keys as a precaution.
What secrets were in the Twitch leak?
GitGuardian found nearly 6,600 secret candidates in the leaked repositories, including 194 AWS keys, 69 Twilio keys, 68 Google API keys, 14 GitHub OAuth keys, four Stripe keys and hundreds of database connection strings. It did not test whether they worked.
Related NHI Mgmt Group resources
Twitter Source Code Leak 2023 · New York Times Breach 2024 · Secrets Management Guide · Leaked Credential Response Playbook · NHI Ownership Guide
How NHI Mgmt Group can help
Most organisations have far more secrets in their code than they think. We help teams measure their secret sprawl, prioritise what matters and put rotation and ownership in place before a leak forces the issue. See our NHI and AI agent security training.
References
- TechCrunch: Twitch confirms hack after source code and creator payout data leaks online (6 October 2021)
- Bitdefender: Misconfigured Server Led to Leak of Twitch Source Code and Proprietary Tools (7 October 2021)
- Twitch: Updates on the Twitch Security Incident (15 October 2021)
- GitGuardian: Twitch Leak, A Deep Dive into the Source Code Security Threats (22 December 2021)