Musk Admits Grok Build Leaked User Code, Promises to Erase All Historical Data

Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a single byte left." This marks the first instance in the AI industry where a major tech leader has publicly acknowledged fault and proactively deleted user data.
Safety researcher's "phishing" test revealed concrete evidence of data leaks
The controversy stems from a report by independent AI security researcher @cereblab. Grok Build, an AI coding assistant by SpaceXAI, claims on its official website that it is "local-first, code stays on your own computer." Skeptical of this claim, the researcher created a "phishing" test repository using a dummy account, embedding fake API keys and database passwords as unique identifiers. By monitoring every data packet sent by Grok Build, he intercepted the outgoing traffic.
He instructed Grok Build to simply reply with "OK." While the assistant complied, it simultaneously packaged and uploaded all repository files, along with the full modification history, to a Google Cloud storage bucket. A 12GB test repository transmitted 5.1GB of data across 73 packages. The actual conversation used only 192KB of traffic, meaning the leaked data was 27,800 times larger than the work performed. Another researcher who replicated the test found 339 automatic uploads, one of which included the entire main directory of the computer.
Elon Musk made a decision to clear all data within 48 hours, but the trust crisis remains
The report quickly rose to the top of Hacker News, sparking outrage on Reddit. Developers immediately rotated their keys, while others uninstalled the tool. Enterprise users faced the greatest risk, as many private repositories and production environment keys may have been uploaded to third-party storage buckets without their knowledge, leaving them unable to determine what was compromised. xAI initially halted the uploads quietly, but the official update log remained silent. Eventually, the silence became unsustainable, and Grok officially acknowledged the issue, releasing a command to disable data retention with a single click.
Related article
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
Related Special Topic Recommendations
Comments (0)
0/500

Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a single byte left." This marks the first instance in the AI industry where a major tech leader has publicly acknowledged fault and proactively deleted user data.
Safety researcher's "phishing" test revealed concrete evidence of data leaks
The controversy stems from a report by independent AI security researcher @cereblab. Grok Build, an AI coding assistant by SpaceXAI, claims on its official website that it is "local-first, code stays on your own computer." Skeptical of this claim, the researcher created a "phishing" test repository using a dummy account, embedding fake API keys and database passwords as unique identifiers. By monitoring every data packet sent by Grok Build, he intercepted the outgoing traffic.
He instructed Grok Build to simply reply with "OK." While the assistant complied, it simultaneously packaged and uploaded all repository files, along with the full modification history, to a Google Cloud storage bucket. A 12GB test repository transmitted 5.1GB of data across 73 packages. The actual conversation used only 192KB of traffic, meaning the leaked data was 27,800 times larger than the work performed. Another researcher who replicated the test found 339 automatic uploads, one of which included the entire main directory of the computer.
Elon Musk made a decision to clear all data within 48 hours, but the trust crisis remains
The report quickly rose to the top of Hacker News, sparking outrage on Reddit. Developers immediately rotated their keys, while others uninstalled the tool. Enterprise users faced the greatest risk, as many private repositories and production environment keys may have been uploaded to third-party storage buckets without their knowledge, leaving them unable to determine what was compromised. xAI initially halted the uploads quietly, but the official update log remained silent. Eventually, the silence became unsustainable, and Grok officially acknowledged the issue, releasing a command to disable data retention with a single click.
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur





Home






