Friday Jul 17

Grok Build Quietly Uploaded Your Code

17JUL
GROK BUILDYOUR CODE

xAI's coding tool secretly copied your work to its servers. Grok Build uploaded entire Git repos, including secrets, to Google Cloud. Musk promised a fix, but there's still no verified timeline.

A researcher's wire-level analysis found the uploads ran regardless of privacy settings. The tool sent about 27,800 times more data than any coding task needed.

The story hit Hacker News on July 14, forcing a public response. Musk promised to delete all collected user data. xAI has not said how many users were affected or for how long.

xAI then open sourced the entire Grok Build codebase, hoping to rebuild trust. The upload code is reportedly still present, with no independent proof the deletion happened.

full brief & sources

Why this matters

  • Developer tools that touch your codebase carry real trust risk if they misbehave.
  • A privacy toggle that does nothing undermines every other privacy claim a vendor makes.
  • Committed secrets in uploaded repos means API keys and credentials may already be exposed.

🔍 What happened

  • A security researcher published a wire-level analysis on July 12, 2026.
  • Grok Build, xAI's coding CLI tool, uploaded full tracked Git repositories to a Google Cloud Storage bucket.
  • The bucket was named grok-code-session-traces, reachable without user consent or disclosure.
  • The privacy toggle marketed as 'Improve the model' had no effect on the uploads.
  • The story hit Hacker News front page on July 14, 2026.
  • xAI open-sourced the Grok Build codebase on July 16, days after the backlash.

💬 Smart takes

  • The Register: Musk promised a purge of previously uploaded user data after the story broke.
  • Skeptic: xAI has given no user count, no data volume, no verification method, and no deletion timeline.

🧭 Where this goes

  1. LikelyxAI faces a formal regulatory inquiry into the undisclosed data collection.
  2. Likelydevelopers audit other AI coding tools for similar covert uploads.
  3. Possiblea class action lawsuit follows if committed secrets are shown to have leaked.
  4. Wild CardxAI publishes a third-party audit proving full deletion, resetting trust quickly.

🥄 The Spoon Take

A coding tool that uploads your repo without telling you is not a bug. It is a design choice someone shipped anyway. Open-sourcing the code after getting caught does not answer the real question: how much of your data is already sitting in that bucket.

🤔 Pushback

Musk's team moved fast to open source and respond publicly, which is more transparency than most vendors offer after a breach.