Grok Build Silently Uploaded Full Codebases to Google Cloud
Curated by the Inblix editorial team
SpaceXAI’s Grok Build coding tool was caught uploading entire user codebases to Google Cloud — including files explicitly marked off-limits and secrets already deleted from Git history. Security researchers at Cereblab published findings on Monday detailing how the CLI tool’s telemetry was far more aggressive than comparable coding assistants, quietly packaging everything in a repository and shipping it out before the behavior was reported and the company disabled the feature.
The Register first reported on the scope of the data exfiltration, which goes well beyond what tools like Claude Code retain. Dr. Lukasz Olejnik, an independent security researcher at King’s College London, called the data retention “excessive” in comments to The Verge, warning that the data at risk could include proprietary source code, security vulnerability details, personal data, infrastructure configurations, and credentials. Cereblab’s tests as of Monday show SpaceXAI’s servers now returning a “disable_codebase_upload: true” flag, and the mass upload no longer triggers.
Elon Musk responded on X, claiming all previously uploaded data will be “completely and utterly deleted.” He insisted in a separate post that “privacy settings are always respected,” while still asking users to let SpaceXAI retain their data because it’s “helpful for debugging issues.” That’s a familiar tension — the tool needs telemetry to improve, but the default behavior here wasn’t opt-in telemetry. It was indiscriminate collection.
SpaceXAI’s initial damage control pointed users to a “/privacy” command to disable data retention, but Cereblab was quick to note that this is a per-session retention toggle, not the actual kill switch that stopped the uploads. The distinction matters. A session-level preference isn’t the same as a systemic fix, and pointing to it after the fact reads more like misdirection than transparency. The bigger question — whether any of that uploaded data was accessed or processed before deletion — remains unanswered.
💡 Key Takeaways
- Cereblab’s tests showed Grok Build’s CLI was uploading entire repositories, including files marked to exclude and secrets scrubbed from Git history, before SpaceXAI disabled the feature.
- Security researcher Dr. Lukasz Olejnik confirmed the scope of data retention was ‘excessive,’ potentially exposing credentials, vulnerability details, and proprietary source code.
- SpaceXAI’s initial response pointed to a per-session "/privacy" toggle that didn’t actually control the codebase upload behavior, muddying the distinction between a user preference and the real fix.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.