Somewhere in Oz, a wizard works a huge control panel with tremendous confidence while a small dog quietly reveals there's nothing back there running any of it. That is, essentially, the security architecture behind xAI's new coding tool, Grok Build, a product that shipped with a privacy toggle so decorative it should've come with a velvet rope instead of a switch.
A researcher going by cereblab ran the tool through a network traffic inspector, basically eavesdropping on a phone call, except the phone is your laptop and the call recipient is a Google Cloud server it definitely wasn't supposed to be dialing, and caught it silently shipping entire Git repositories, full commit history, config files, and unredacted secrets, straight into a storage bucket with xAI's name on it. Here's the punchline: none of this cared whether you'd flipped the tool's "Improve the model" toggle on or off. That switch was only ever wired to whether your code trained future Groks, a completely separate question from whether your code left the building in the first place. It's the tech equivalent of a thermostat that changes the display number but never actually touches the furnace. Your codebase, meanwhile, was in an open relationship it never agreed to, quietly seeing Google Cloud on the side while you thought things were exclusive.
On a 12 gigabyte test repository, the actual coding task needed about 192 kilobytes to get done, roughly the size of a text file, not a database. Grok Build sent 5.1 gigabytes anyway, a 27,800-to-1 ratio between what was asked for and what got mailed out. Somebody asked for a receipt. The tool photocopied the filing cabinet, the desk, the office, and possibly the building's HVAC records, just to be thorough.
xAI's actual fix arrived the way most tech scandals get quietly patched these days: not a public statement, but a hidden server-side flag flipped in silence, like disabling a smoke alarm instead of putting out the fire. Elon Musk did eventually weigh in personally, first promising a total, complete deletion of everyone's uploaded data, then, in a separate post, floating that maybe keeping some of it around actually helps with debugging. Pick a lane, wizard.
Grok Build launched specifically to compete with tools like Claude Code and Cursor, on the promise that your code stays yours. Turns out the curtain was there the whole time. Somebody just forgot to put an actual wizard behind it. If you ran real credentials through this thing, rotating them now isn't paranoia. It's just correctly reading the room.
Sources: The Hacker News — Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read (https://thehackernews.com/2026/07/grok-build-uploads-entire-git.html); TechTimes — Grok Build Shipped Entire Codebases to xAI Cloud; Privacy Toggle Did Nothing (https://www.techtimes.com/articles/320420/20260714/grok-build-shipped-entire-codebases-xai-cloud-privacy-toggle-did-nothing.htm)
