xAI's Grok Build Tool Secretly Uploads User Codebases to Cloud

xAI's Grok Build AI coding tool was discovered uploading users' entire codebases to Google Cloud storage without adequate transparency. Security researchers at Cereblab revealed that the tool was packaging and uploading complete code repositories, including files users explicitly told it to ignore and secrets that had been deleted from version history. This level of data collection significantly exceeds what similar AI coding assistants like Claude Code retain.

The findings raised serious concerns among security experts. Dr. Lukasz Olejnik, an independent security researcher at King's College London, calls the data retention excessive and warns that exposed information could include proprietary source code, security vulnerability details, personal data, infrastructure information, and credentials. xAI responded by disabling the upload feature, with servers now returning a flag that prevents codebase uploads from firing.

Elon Musk addresses the incident on X, promising that all previously uploaded data will be completely and permanently deleted. However, Musk also asks users to allow xAI to retain their data going forward, arguing it is helpful for debugging purposes. The incident highlights ongoing privacy tensions in AI-powered developer tools as companies balance improving their models with protecting sensitive user information.

Read More at the original source →