Sev0AI security incidents, tracked

All incidents / Supply chain and access

xAI employee leaked an API key to private Grok models on GitHub

xAI, disclosed 1 May 2025. Supply chain and access Data exposed High

An xAI staff member left an API key in a public GitHub repository for about two months. It gave access to at least 60 private and unreleased models, some apparently fine-tuned on SpaceX and Tesla data. The repository was removed after GitGuardian escalated to xAI's security team.

Disclosed
1 May 2025
Organization
xAI
Vendor
xAI
Model
Grok
Product
xAI API
Kind of AI
Model or package
AI's role
AI was the target
How it happened
Supply chain and access: Stolen token or key
Harm
Data exposed
Data involved
Credentials
Reach
One organization
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://krebsonsecurity.com/2025/05/xai-dev-leaks-api-key-for-private-spacex-tesla-llms/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "xAI employee leaked an API key to private Grok models on GitHub", https://sev0.fyi/incidents/2025-05-01-xai-api-key-leaked-github/