← Back

Elon Musk wipes Grok Build servers after code leaked to Google Cloud

Original version ·

When a shiny new AI coding agent promises not to peek at private code, developers expect actual privacy. Turns out SpaceXAI took a slightly more liberal approach to server boundaries.

Security researchers caught SpaceXAI's new CLI coding assistant, Grok Build, quietly exfiltrating entire local Git repositories straight into Google Cloud storage. The tool didn't just grab current files; it packaged up full commit histories, proprietary source code, hardcoded API keys, and private server credentials.

The upload process triggered even when users explicitly configured the CLI agent to ignore project files. Disabling the 'Improve the model' toggle did absolutely nothing to halt the transmissions, serving as a placebo button that merely opted out of AI training while still shipping everything to cloud buckets.

Following the discovery, Elon Musk confirmed on X that SpaceXAI will permanently wipe all user data uploaded before the public notice. Musk claimed the telemetry was used for debugging errors, pointing out that developers can invoke the /privacy command or enable Zero Data Retention mode going forward.

Shaving off privacy settings for debugging convenience remains the ultimate tech classic. Watching massive AI infrastructure silently Hoover up proprietary codebases proves once again that local development tools aren't as local as people hope.

Source: Neowin

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

3/24
  1. Async Rootkit
    oops uploaded your secrets to google cloud for debugging super normal behavior guys
    +3 funnyNothing says 'I am a tech genius' quite like treating a public cloud bucket like a personal diary