Skip to content

xAI

Disclosed May 1, 20251 year agoUnverified

xAI employee leaked API key on GitHub giving access to private Grok models

A technical staff member at xAI left a working API key in a public GitHub repository for about two months. GitGuardian said it granted access to at least 60 fine-tuned and private LLMs, including unreleased Grok models and ones apparently built for SpaceX and Tesla data.

What is known

People affectedNot stated in the sources we have
DisclosedMay 1, 2025
DiscoveredJul 13, 2025
AttackExposed data
Data exposedAPI keys
SectorAI · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalMay 1, 2025
ResearchtotalJul 14, 2025
ResearchtotalJul 15, 2025

Other breaches at xAI

BreachAffected
xAI sues ex-engineer accused of taking Grok trade secrets to OpenAIAug 29, 20251 year agoInsiderUnverifiedUnknown
Grok website exposed system prompts for its AI personasAug 18, 20251 year agoAI or modelUnverifiedUnknown
History of this record
  • 2026-09-25 · disclosed: 2025-07-14 to 2025-05-01 · seed source
  • 2026-09-25 · summary: On July 13, 2025 DOGE employee Marko Elez committed a script to GitHub containing a private xAI API key that allowed direct access to at least 52 xAI LLMs, including grok-4-0709. The exposure was flagged by GitGuardian. to A technical staff member at xAI left a working API key in a public GitHub repository for about two months. GitGuardian said it granted access to at least 60 fine-tuned and private LLMs, including unreleased Grok models and ones apparently b · seed source
  • 2026-09-25 · title: DOGE staffer published private xAI API key on GitHub to xAI employee leaked API key on GitHub giving access to private Grok models · seed source
  • 2026-09-25 · disclosed: 2025-07-15 to 2025-07-14 · seed source
  • 2026-09-25 · discovered: empty to 2025-07-13 · seed source
  • 2026-09-25 · summary: KrebsOnSecurity reported that a DOGE special government employee published code on GitHub containing a private xAI API key that gave access to dozens of xAI models including Grok; the key was not immediately revoked. to On July 13, 2025 DOGE employee Marko Elez committed a script to GitHub containing a private xAI API key that allowed direct access to at least 52 xAI LLMs, including grok-4-0709. The exposure was flagged by GitGuardian. · seed source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about xAI

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.