WeSearch

I built a scanner that found 41 live AWS keys in 900 Terraform state files

·3 min read · 0 reactions · 0 comments · 12 views
#aws#security#terraform
I built a scanner that found 41 live AWS keys in 900 Terraform state files
⚡ TL;DR · AI summary

A security researcher discovered 41 live AWS keys in 900 Terraform state files while scanning S3 buckets. The researcher created a scanner to identify these vulnerabilities after facing challenges reporting them to companies. As a solution, they developed an open-source tool to prevent such exposures in the future.

Key facts
Original article
Vechron
Read full at Vechron →
Opening excerpt (first ~120 words) tap to expand

Vechron > Security > I found 900 S3 buckets exposing Terraform state files. 41 had live AWS credentials. Security I found 900 S3 buckets exposing Terraform state files. 41 had live AWS credentials. Last updated: 2026/05/25 at 11:39 AM Piyush Gupta Share 4 Min Read $20 VPS. 72 hours. 900 buckets. 40 live AWS keys. (Screenshot is an AI-generated recreation for illustration. No real credentials are shown.) SHARE I built a scanner that guesses S3 bucket names and looks for .tfstate files. Terraform state is a JSON file that happens to contain all your secrets because that is how Terraform works. I ran it for three days on a cheap VPS and found 900 state files. 40 of them had raw AWS keys sitting in plaintext. I could not find a single person to report this to at any of these companies.

Excerpt limited to ~120 words for fair-use compliance. The full article is at Vechron.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from Vechron