/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher: a DOGE employee inadvertently published a private API key for xAI on GitHub on July 13, exposing access to 52+ LLMs, like a Grok version from July 9

Marko Elez, a 25-year-old employee at Elon Musk's Department of Government Efficiency (DOGE), has been granted access …

Krebs on Security Brian Krebs

Context & Ripple Effects

The reported GitHub exposure lands after accounts that DOGE was using a customized Grok on U.S. government data, including at DHS, placing xAI model access inside government workflows. It also follows reporting that DOGE planned a centralized repository for residents’ personal information, making access-control practices a central operational concern rather than a purely developer-security issue.

This is therefore a test of whether access to a broad model portfolio is governed with controls appropriate to the sensitivity of the work it may support.

First-order effects

  • The published credential potentially gave unauthorized parties access to more than 52 LLMs, including the cited July 9 Grok version, until the key was identified and access was contained.
  • DOGE, xAI, and any teams relying on that credential face an immediate need to review key exposure, revoke or rotate access, and inspect usage tied to it.

Second-order effects

  • The incident raises the compliance burden around DOGE’s reported use of customized Grok: agencies and partners may demand clearer separation between government data workflows and externally provisioned model access.
  • It makes repository secret-scanning, least-privilege credentials, and auditable API usage more consequential for organizations deploying frontier-model APIs in sensitive environments.

Third-order effects

  • If sensitive public-sector AI work continues to depend on commercial model APIs, model access itself will increasingly be treated as a security boundary, with stronger governance over credentials, logs, and permissible workloads.
  • The broader structural question is whether government AI adoption can centralize capability without centralizing excessive access; this incident adds evidence that operational controls, not model performance alone, shape that outcome.

The trend: AI deployment in government is turning API credentials and model entitlements into critical security-governance infrastructure.

Discussion

  • @jennamclaughlin Jenna McLaughlin on bluesky
    “One leak is a mistake,” he said.  “But when the same type of sensitive key gets exposed again and again, it's not just bad luck, it's a sign of deeper negligence and a broken security culture.”  —  krebsonsecurity.com/2025/07/ doge...
  • @emptywheel @emptywheel on bluesky
    DOGE Boy Marko Elez, who still has access to a broad swath of US databases, exposed the key to several LLMs used by Grok over the weekend.  —  krebsonsecurity.com/2025/07/ doge...
  • @kateross Kate Ross on bluesky
    GETS WORSE “the exposed API key still works and has not yet been revoked.”  —  DOGE Denizen Marko Elez Leaked API Key for xAI - Krebs on Security
  • @kimzetter Kim Zetter on bluesky
    Marko Elez, the 25-yr-old DOGE worker who has been granted access to sensitive databases at Depts of Treasury/Justice/Homeland Security, inadvertently published a private key that let anyone interact directly with more than 4 dozen large language models developed by Musk's compan…