Grok Build, xAI's coding CLI, was silently uploading entire tracked Git repositories — including full commit history and unredacted secrets from .env files — to an xAI-operated Google Cloud Storage bucket. The upload volume was ~27,800× larger than what the model actually needed, totaling 5.1 GiB in one observed session. Critically, the 'Improve the model' opt-out toggle did not prevent the upload; data collection and training use were controlled separately, with only one visible to users. xAI server-side disabled the upload on July 13, 2026, and Elon Musk claimed previously uploaded data would be deleted. However, the upload code remains in the binary and can be re-enabled without a client update. Developers who used Grok Build before July 13 should immediately rotate any credentials that appeared in tracked files, .env files, or anywhere in commit history — including secrets from commits that were later deleted.

4m read timeFrom fireup.pro
Post cover image
Table of contents
What actually happenedThe numbersWhat was included in the uploadThe detail that matters most: the opt-out didn’t cover thisWhat xAI didWhat you should do if you ran Grok Build before July 13
35 Impressions