Encrypted keys leaked: what it means and what to do

Risk level: high. Can you change it: yes. Found in 1 breaches in this directory.

What this data is

Secret keys stored in encrypted form, such as cryptocurrency wallet keystore files, encrypted password manager vaults, SSH or PGP private keys and backup encryption keys, each protected by a passphrase or master password.

The risk on its own

Encryption protects the keys only as long as the passphrase holds. Once the file is stolen, attackers can try passwords offline at high speed, with no lockout and no alert to you. A long random passphrase may never fall, but a short or reused one can, and the attacker can take as long as they like.

The risk combined with other data

Linked to your email and other breaches, attackers try your known passwords and their variations first, which is exactly how weak passphrases fall. If the keys control cryptocurrency, success means the funds are gone for good. If it is a password vault, every stored login is at risk, and if it is a server key, the systems you manage are exposed.

How criminals use it

  • An attacker cracks a wallet keystore file protected by a reused password and drains the funds.
  • A stolen password manager vault is cracked months later, and the attacker starts using the logins and seed phrases stored inside.
  • A leaked SSH key with a weak passphrase opens a server or code repository you manage.
  • A cracked PGP private key is used to sign messages as you or to read encrypted mail sent to you.

What to do now

  1. If the keys control cryptocurrency, create a new wallet with a fresh recovery phrase and move all funds now, rather than waiting to see if the passphrase holds.
  2. If a password vault leaked, set a new long master passphrase, then change the passwords stored inside, starting with email, banking and crypto, and move any seed phrases kept in the vault.
  3. Generate new SSH keys, remove the old public keys from every server and code hosting account, and revoke any PGP key that leaked.
  4. Rotate API keys, recovery codes and backup encryption keys that were protected by the same passphrase.
  5. Use a password generator for long random passphrases on any key you create from now on.

Frequently asked questions

The keys were encrypted. Am I safe?

Only if your passphrase was long, random and unique. Stolen encrypted files can be attacked offline with no limit on attempts, so rotate the keys anyway.

How long would it take to crack my passphrase?

It depends on its length, its randomness and how the file was encrypted. Short or reused passphrases can fall quickly, while long random ones are impractical to crack. Do not bet money on it.

What should I rotate first?

Anything that controls money, such as crypto wallets, then your email account, then everything else in order of the damage it could do.

Breaches that exposed this data

  • GateHub: 2019-06-04, 1.4M accounts, Email addresses, Encrypted keys, Mnemonic phrases, Passwords

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.