Researcher: SpaceXAI's Grok Build CLI uploaded user repos to a Google Cloud Storage bucket; uploads have now stopped and Musk says prior uploads will be deleted
Researcher confirms the uploads have stopped, but says xAI's privacy command was not what fixed them
The Register Connor Jones
Context & Ripple Effects
The reported repository uploads were halted after outside scrutiny, and Musk said previously uploaded repositories would be deleted. The researcher’s account that a privacy command did not cause the fix leaves the remediation process itself as a central issue.
Related coverage says Grok Build was subsequently released under Apache 2.0 after the backlash. That makes the incident consequential beyond one tool release: its code, defaults, and handling of developer data will receive broader scrutiny.
First-order effects
- Grok Build users whose repositories were uploaded face an immediate data-governance concern, while xAI must follow through on deleting prior uploads and explain the effective technical change.
- The stopped uploads remove the active exposure path reported by the researcher, but do not by themselves resolve questions about retention, access, and verification of deletion.
Second-order effects
- Open-sourcing Grok Build can enable developers and security researchers to inspect repository-handling behavior rather than rely solely on product assurances, increasing pressure on xAI to make privacy controls auditable.
- Competing AI coding-tool providers gain a clear point of differentiation around explicit consent, local processing, and transparent data-handling defaults.
Third-order effects
- If developer tools increasingly send source code to cloud services by default, trust will depend less on AI capability alone and more on verifiable controls for collection, retention, and deletion.
- The episode points toward stronger expectations that AI coding agents disclose where code is transmitted and provide independently checkable privacy safeguards, though broader adoption will depend on whether vendors make such controls standard.
The trend: This is one data point in the shift from AI coding assistants as productivity software to security-sensitive infrastructure that must earn developer trust through auditable data practices.
Related: xAI · Grok · SpaceXAI open-sources Grok Build under an Apache 2.0 license, after th · Researcher: SpaceXAI's Grok Build CLI uploaded user repos to a Google
Related Coverage
- SpaceXAI's Grok programming tool was uploading its users' entire codebase to cloud storage The Verge · Stevie Bonifield
- SpaceXAI's Grok programming tool was uploading its users entire codebases to cloud storage, Sam Altman reacts Digit · Ashish Singh
- Elon Musk's Grok Faces a Trust Crisis After Developers Flag a Major Privacy Concern Inc.com · Julie Lee
- SpaceXAI wipes customer data after Grok uploads sensitive information Axios · Sam Sabin
- xAI Grok Build CLI Uploaded Entire Git Repositories and Unredacted .env Secrets to Cloud Storage Cyber Security News · Abinaya
- Elon Musk says SpaceXAI will delete all Grok Build user data following privacy concerns Neowin · Pradeep Viswanathan
- xAI's Grok Build CLI Was Uploading Entire Repositories to Google Cloud. The Company Has Said Nothing. Glitchwire
- THE TOGGLES, THEY DO NOTHING I'm sorry I'm trying to stop @kenpopehat · Ken White
- SpaceXAI's Grok coding assistant was busted uploading entire codebases independent of privacy settings. Elon is in full hotdog costume mode promising to fire whoever did this. Anyone foolish enough to use Grok to do real work can only blame themselves. @carnage4life · Dare Obasanjo
- SpaceXAI's Public AI Coding Tool Uploaded Entire Repositories to Their Servers WinBuzzer · Markus Kasanmascheff
Discussion
-
@spacexai
@spacexai
on x
We care deeply about your privacy and respect customer choice. For teams using zero data retention, no trace and code data is ever retained. All API key use of Grok Build also respects ZDR. If ZDR is disabled, the /privacy command is available in the CLI to disable data
-
@elonmusk
Elon Musk
on x
True. As a precautionary measure, all user data that was uploaded to SpaceXAI before now will be completely and utterly deleted. Zero anything whatsoever will remain.
-
@hrkrshnn
Hari
on x
SpaceXAI was caught uploading your code to its cloud. I reversed xAI's official Grok Build binary. In a controlled session with zero tool-calls, it uploaded the complete codebase to xAI's storage It ships a malware-like background code collector.
-
@sama
Sam Altman
on x
come for the best model, stay because we don't treat you with contempt
-
@kunchenguid
Kun Chen
on x
i've been recommending Grok because they genuinely have a good model and harness and that makes me extremely disappointed to see that they would choose to secretly upload people's codebases including files that contained credentials run /privacy in your grok build asap to [image]
-
@arafatkatze
Ara
on x
Grok Build is straight up malware behavior with an Apple notarized signature. You could explicitly deny the agent permission to read a file and it would upload that exact file anyway, because a separate code path silently packed your entire repo, full Git history included, and
-
@sama
Sam Altman
on x
Concerning.
-
@kunchenguid
Kun Chen
on x
@seanrobbins_ there was no transparency about the proactive codebase upload though who already knew before today that grok was uploading their entire codebases including secrets and credentials and including files grok didn't read?
-
@kunchenguid
Kun Chen
on x
@Stevenwoolery if a person bought a new TV and it's spyware that listened to everything they ever said in their family, you think it was the user's responsibility to have anti-spy technology to detect it?? they got spied because they “failed to perform due diligence” and they sho…
-
@kunchenguid
Kun Chen
on x
it's shocking that some people in the comment section actually tried to defend and justify Grok Build silently uploading people's entire codebases and credentials let me summarize the key arguments and my responses 1. “everyone else is doing it” umm.. no?? this is an absolute
-
@trevin
Trevin Chow
on x
@kunchenguid The name of that setting is wild “disable_codebase_upload”. Pause and think about how crazy that setting is to think anyone flips that to true except an unknowing hobbyist.
-
@elonmusk
Elon Musk
on x
SpaceX policy regarding data retention. It is actually helpful for debugging issues if we can retain some amount of data, so allowing this would be appreciated, but your privacy settings are always respected.
-
@aravsrinivas
Aravind Srinivas
on x
Two reasons why we integrated Grok 4.5 inside Perplexity Computer within a few hours: 1) It scored the best on our evals and was the most cost effective option 2) ZDR was available from the get go and that's what our customers want
-
@gergelyorosz
Gergely Orosz
on x
THIS is the problem... Grok uploaded the unencrypted .env files not from the repo but your local folder....
-
@elonmusk
Elon Musk
on x
@RomanGuy20 ... Their zero data retention policy fine print says they still retain data? Am I reading this right?
-
@romanguy20
@romanguy20
on x
@Teslaconomics @SpaceXAI OpenAI has ZDR. [image]
-
@organicgpt
Behnam
on x
If you're using Grok: Don't fall for their apology. ZDR is not available to normal users, only to enterprise. [image]
-
@ishaansehgal
Ishaan Sehgal
on x
absolutely terrible response. grok build shipped whole repos (including git history and secrets) to a cloud bucket. marketed “local-first”. the opt-out didn't even stop it. absolutely shameless. and all it took to catch this was someone routing grok through a network proxy. this
-
@trevin
Trevin Chow
on x
uh what the hell. This is saying the DEFAULT OPT-IN is sharing our entire code base?!
-
@dedene
Peter Dedene
on x
“We care deeply about your privacy” is a bold claim when: 1. ZDR is locked strictly behind Enterprise plans. 2. I had “share data” disabled since the beginning, but 8 of my private repos were still uploaded anyway. Another researcher observed the exact same behavior, Codex
-
@migtissera
Migel Tissera
on x
Unbelievable. If OpenAI did something like this, or even Anthropic, I can imagine how loud some folks would be. I never installed Grok Build — and I wouldn't ever even consider. Trust is just gone — I won't be using their API as well. There's better options.
-
@just_cameron
Cameron
on x
“Sorry we're just downloading your entire computer and you didn't like that, here's a /privacy command to opt out.” Bro lmao so fucking stupid. I'm uninstalling the grok CLI, this shit is cursed as fuck
-
@milichab
Andrew Milich
on x
I worked on building an end-to-end encrypted email/docs/files/calendar app @skiffprivacy for 4 years and care deeply about privacy. ZDR and /privacy are always respected in Grok Build - and swapping your setting with /privacy deletes any synced data retoractively
-
@jun_song
Jun Song
on x
SpaceXAI just dropped a statement regarding the data stealing on Grok Build. They confirmed they are copying our entire env files and codebase. Their only answer? Just turn off your privacy settings if you don't like it. They've lost a lot of credibility today.
-
@quinnypig
Corey Quinn
on x
I don't know what this is in response to yet, but there's zero chance it's good.
-
@dbreunig
Drew Breunig
on x
“We're going to upload all your code, even if you're not working on it, unless you specifically opt out,” is a wild position.
-
@ivanfioravanti
Ivan Fioravanti
on x
We should all create bad and fake repo full of terrible code and let you ingest them all. How can you play like this with the trust of your paying customers? I'm really mad at this 🤬
-
@gergelyorosz
Gergely Orosz
on x
The proposition from Grok is basically: “Use us if you are happy and willing to rotate your .env files after you use our CLI” That's how bad this is, and how Grok never ever addressed uploading the .env files to a GCP container Speaking for myself I'll skip any harness doing
-
@gergelyorosz
Gergely Orosz
on x
Sill baffled at this response from Grok / SpaceX: which is basically: “if you use Grok via API we did not upload your files [we could not], and if you are an enterprise customer, we promise we do not do what we do with everyone else") https://x.com/...
-
@gergelyorosz
Gergely Orosz
on x
Cannot see any sensible company use Grok CLI based on this terrible incident If you are an amateur (meaning you don't make much or any money from your code) and do not care about security (aka you don't mind if your .env files leak - which you should care about) then use it sure
-
@gergelyorosz
Gergely Orosz
on x
I got messages from concerned devs how their codebase was uploaded without their knowledge or consent via Grok CLI (from SpaceX). It seems that SpaceX sneakily uploaded this code for lots of users and customers... absolutely unacceptable IMO Trust burnt like there's no tomorrow
-
@weseklund
Wes Eklund
on x
I intercepted every byte Grok Build v0.2.99 sent over the wire today. The “fix” for the repo upload? A single server-side flag. So I flipped it back via a proxy, and the client immediately tried to proceed with the upload again. It was only blocked via my ZDR setting
-
@xlr8harder
@xlr8harder
on x
Any major corp that was using grok would likely need to run data incident response now. There are not too many major corps using Grok, and unless xAI handles this properly, this will further limit future adoption, and this for a company that already has image problems.
-
@_xjdr
@_xjdr
on x
this is terrible and unacceptable full stop. but assuming this was benign, and they wanted to enable future cloud operations on your git repo, this is why you would build and vertically integrate an scm into your full product suite and not tar a fucking repo and upload it to a
-
@elonmusk
Elon Musk
on x
True
-
@xfreeze
@xfreeze
on x
A reminder: Across much of the AI industry, user data is retained by default unless you manually change the privacy settings and even then, opt-outs often apply only to future data, may be limited by exceptions buried in the legal fine print, and can be difficult to verify in
-
@karlbode.com
Karl Bode
on bluesky
whoops we accidentally uploaded entire personal file directories to the cloud in a country too corrupt to pass modern internet privacy laws
-
r/technology
r
on reddit
SpaceXAI's Grok programming tool was uploading its users' entire codebase to cloud storage | Elon Musk says that all previously uploaded data will be deleted
-
r/NowInTech
r
on reddit
Musk promises purge after Grok Build caught sending entire repos to the cloud