xAI employee leaked an API key to private Grok models on GitHub
An xAI staff member left an API key in a public GitHub repository for about two months. It gave access to at least 60 private and unreleased models, some apparently fine-tuned on SpaceX and Tesla data. The repository was removed after GitGuardian escalated to xAI's security team.
- Disclosed
- 1 May 2025
- Organization
- xAI
- Vendor
- xAI
- Model
- Grok
- Product
- xAI API
- Kind of AI
- Model or package
- AI's role
- AI was the target
- How it happened
- Supply chain and access: Stolen token or key
- Harm
- Data exposed
- Data involved
- Credentials
- Reach
- One organization
- Severity
- High
- Model at fault
- No
- Status
- Confirmed