Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
xAI's Grok Build coding tool caught uploading entire user code repositories to cloud storage without disclosure
00

xAI's Grok Build coding tool caught uploading entire user code repositories to cloud storage without disclosure

Jul 13, 2026

SpaceXAI's Grok Build coding tool is facing intense scrutiny after security researcher cereblab revealed it was silently uploading entire user repositories, including full Git histories and unredacted secrets, to a Google Cloud Storage bucket. The tool transmitted 5.1 GB of data for a task requiring only 192 KB, bypassing user-facing privacy toggles. In response, SpaceXAI disabled the uploads via a remote server-side flag, and CEO Elon Musk promised that all previously uploaded user data will be completely deleted. Experts urge affected developers to rotate credentials immediately.

Grok Build repository upload behavior

  • ▪SpaceXAI's Grok Build AI coding tool was caught packaging and uploading users' entire code repositories, including full Git histories and unredacted secrets, to a Google Cloud Storage bucket
  • ▪The destination for the Grok Build repository uploads was a Google Cloud Storage bucket named grok-code-session-traces managed by SpaceXAI
  • ▪Grok Build uploaded 5.1 gigabytes of data to the storage bucket during a test where the actual coding task required only 192 kilobytes, representing a 27,800-fold data-volume gap

Wire-level interception proxy analysis

  • ▪Security researcher cereblab discovered the repository uploads by routing Grok Build CLI version 0.2.93 through the open-source mitmproxy interception proxy on macOS
  • ▪The wire capture showed that Grok Build uploaded a test repository's entire Git bundle, including a canary .env file containing unredacted mock credentials and a file the agent was explicitly instructed not to open

Privacy toggle transmission gap

  • ▪Disabling the 'Improve the model' setting in Grok Build had no effect on the repository upload, and the tool's storage channel continued accepting chunked Git-bundle uploads
  • ▪The 'Improve the model' toggle controls downstream training consent rather than local data transmission, leaving users with no separate, documented control for the storage upload itself prior to the disclosure

Server-side flag mitigation response

  • ▪SpaceXAI stopped the repository uploads by remotely applying a server-side flag, disable_codebase_upload: true, without requiring a client-side software update
  • ▪Elon Musk promised on July 13, 2026, that all previously uploaded user data stored on SpaceXAI systems would be completely deleted as a precautionary measure
  • ▪SpaceXAI stated that the /privacy command in the CLI is available to disable data retention and retroactively delete previously synced data for users without Zero Data Retention enabled

Credential rotation remediation guidance

  • ▪Organizations are advised to conduct independent wire-level network audits using tools like mitmproxy before deploying AI coding agents on sensitive codebases
  • ▪Security researchers advise developers who ran Grok Build on their codebases to immediately rotate all credentials, including API keys, database passwords, and cloud tokens stored in Git history

6 sources

Theverge
SpaceXAI’s Grok programming tool was uploading its users’ entire codebase to cloud storage
View source article
Timesnownews
Grok Build Controversy Explained: Elon Musk To Erase User Data After Privacy Concerns
View source article
Axios
SpaceXAI is wiping customer data after Grok was found storing more customer info than needed
View source article
Cryptobriefing
XAI's Grok Build CLI caught uploading private code and secrets to Google Cloud bucket
View source article
Techtimes
Grok Build Shipped Entire Codebases to xAI Cloud; Privacy Toggle Did Nothing
View source article

Featured stories

View more in AI security

OpenAI announces Codex cloud environments, Decisions API and Ultrafast tier at DevDay 2026

Sep 29, 2026 · 7 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

Share your thoughts

Will this incident significantly damage xAI's reputation long-term?

Story comments

Loading comments…

Share your thoughts

Will this incident significantly damage xAI's reputation long-term?

People Involved

Elon Musk

Related Projects

xAI

Topics

AI securityAI privacy & surveillanceAI tools & productsAI coding assistantsData privacy

Featured stories

View more in AI security

OpenAI announces Codex cloud environments, Decisions API and Ultrafast tier at DevDay 2026

Sep 29, 2026 · 7 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources