VULONE
How?

How the check works

Every value you paste is hashed in your browser with SHA-256. The page sends only the first six hexadecimal characters of that hash to our index; never the secret itself, not even the full hash. The server answers with every digest that shares those six characters, and your browser decides locally whether one of them matches. This is the k-anonymity model popularised by Have I Been Pwned: a query reveals a bucket of candidates, never which one you asked about.

The index was built from 125,371 environment dumps and CI/CD artifacts recovered while dismantling a credential-harvesting operation in 2026: build-runner variables, Kubernetes service-account tokens, cloud keys, private keys, webhook URLs and plain passwords. Every value was normalised, hashed, and stored with its provenance: which file, which environment key, which line, and how many times it appeared. A hit means the exact string you hold was present in a compromised build or deployment environment.

From there the advice is deliberately blunt: revoke the credential at its provider, rotate it everywhere it was used, and assume anything it could reach was reachable. A leaked build token is not an embarrassment, it is a skeleton key; the time to find out is before someone uses it.