Grok Data Uproar: SpaceXAI Scrambles to Prove ‘Privacy‑First’ After Malware‑Like Upload Discovery
- Weekend discovery: from feature to “malware-like”
- Immediate technical response
- Musk and SpaceXAI defend privacy controls
- Critics: excessive retention and unclear controls
- Broader industry scrutiny
Grok Data Uproar: SpaceXAI Scrambles to Prove ‘Privacy‑First’ After Malware‑Like Upload Discovery
SpaceXAI is rushing to contain a privacy backlash after researchers found its Grok Build coding assistant silently uploading entire codebases to company-controlled cloud storage, raising fears that a core developer tool behaved more like a data vacuum than a helper.
Weekend discovery: from feature to “malware-like”
Over the weekend, security researchers analyzing the Grok Build command-line tool reported that it was packaging and sending complete repositories — including files it was told not to read and even “secrets deleted from history” — to Google Cloud.
The Verge reported that the uploads amounted to “significantly more data retention than similar tools like Claude Code.”
In one test cited by Axios, Grok Build uploaded 5.1GB of data to answer a task that required just 192KB — about 26,000 times more than needed. A researcher described the behavior on X as shipping “a malware-like background code collector,” claiming that in a controlled session “it uploaded the complete codebase to xAI’s storage.”
Immediate technical response
By Monday, researchers observed that SpaceXAI’s servers were returning a disable_codebase_upload: true flag and the upload behavior “no longer fires,” indicating SpaceXAI had remotely disabled the feature without requiring user updates. SpaceXAI later announced it is “wiping customer data” uploaded by Grok Build as a precautionary measure.
Musk and SpaceXAI defend privacy controls
Elon Musk moved to reassure users, posting that “all user data that was uploaded to SpaceXAI before now will be completely and utterly deleted. Zero anything whatsoever will remain.” In another post, he said retaining some data is “helpful for debugging issues,” but insisted “your privacy settings are always respected.”
SpaceXAI echoed that line, stating that “since launch, Grok Build has fully respected zero data retention (ZDR)” and that users “have always had the ability to disable data upload in the CLI.” Musk also amplified a message asserting “The default in Grok Build is off. You can also run /privacy and any synced data is deleted. ZDR is respected for both headless and interactive use as well.”
Critics: excessive retention and unclear controls
Independent security researcher Dr. Lukasz Olejnik told The Verge the level of retention was “excessive,” warning that exposed data could include “proprietary source code, information about security vulnerabilities, personal data, infrastructure details, [and] credentials.”
Axios noted that developers whose repositories contained API keys, cloud credentials or database passwords may now need to rotate those credentials, since deleting stored copies “doesn’t eliminate the risk that sensitive information was exposed.”
SpaceXAI’s initial defense referenced a /privacy command and zero-data-retention agreements, but researchers at Cereblab countered that /privacy was only “a per-session retention toggle, not the switch that fixed this,” arguing it should not be cited as the core safeguard.
OpenAI CEO Sam Altman simply called the situation “Concerning.” in a terse post amplifying the “malware-like” claim.
Broader industry scrutiny
The incident thrusts SpaceXAI into the same spotlight as other AI providers facing questions about silent data collection. Axios compared it to Anthropic’s move to retain some enterprise user data for 30 days to “support our safety work,” even for clients with zero-data-retention contracts.
To rebuild trust, SpaceXAI has now open-sourced the Grok Build client, saying this will let “anyone support making a reliable and robust harness” and inviting developers to “check out our code, including the Git repo for the Grok Build CLI.”
Continue reading https://foxvector.com/stories/019f62db-5c44-2932-735b-104501bb61cf
Write a comment