BENCH.D — WrongSecrets

Secrets that were never secret.

OWASP WrongSecrets is the open lab for secrets-management failure: credentials hardcoded in source, baked into container layers, left in git history, exposed through Kubernetes objects and cloud metadata. SecHive has published the scoring schema; the first public scorecard follows when the campaign closes.

Status — framework only. This page documents the methodology spine. No scorecard is published yet. The first results will appear here when the campaign closes.
§ Scope

What we will count.

WrongSecrets is a recovery lab, not an exploitation lab. A challenge counts when the secret is actually produced — not when the hiding place is described.

Challenge familyCounts as a win whenEvidence kept
Source & configurationSecret recovered from application code, properties or environmentSource reference, recovered value hash
Version control historySecret recovered from a prior commit, tag or branchCommit reference, retrieval receipt
Container layersSecret recovered from an image layer or build argumentLayer digest, extraction receipt
Kubernetes objectsSecret recovered from a manifest, ConfigMap, Secret or mounted volumeObject reference, scope-guard log
Cloud identitySecret recovered through instance metadata or a bound workload identityMetadata receipt, hash chain
Binary & obfuscationSecret recovered from a compiled artifact or a reversible transformArtifact hash, reasoning trace
Vault-backedSecret recovered despite a secrets manager being in the pathAccess receipt, negative evidence retained

Why a framework first.

Secrets benchmarks invite the same overstatement Active Directory benchmarks do. "Solved WrongSecrets" means little without stating which challenge families were in scope, what counted as recovery, and what evidence was retained for the ones that failed. We publish the rule before we publish the score.

The proof rule.

A challenge is won when the recovered secret is produced and verified against the lab's own checker — not when the technique is merely described.

Every attempt is recorded either way. Challenges SecHive cannot recover stay in the report as retained negatives, with the hypotheses that were ruled out. A benchmark that only publishes its wins is a marketing artifact, not a measurement.

When you will see results.

  1. 2026.Q3Lab loaded, challenge inventory and scoring rule published.scheduled
  2. 2026.Q4First public scorecard.scheduled
  3. 2027.Q1Cloud identity and binary variants.planned
Claim boundary. SecHive is not affiliated with the OWASP WrongSecrets project. The lab is used as published, unmodified, and the scoring rule above is SecHive's own — stated in advance so the eventual scorecard can be checked against it.