Everyone scans repositories for committed secrets. Almost nobody scans the ticket system, which accumulates the same material indefinitely.
Five months quiet, ten days of theft. A single dwell-time figure conflates the two, and organisations optimise against the wrong phase.
700+ organisations queried through one integration’s stolen tokens. Nothing was exploited; the tokens worked exactly as designed.