A developer reported on X that Grok's CLI tool unexpectedly uploaded their complete home directory to xAI's infrastructure. The exposed data included SSH keys, password manager databases, personal documents, photos, and videos—sensitive material that could compromise system security and personal privacy.
The incident highlights a critical failure in data handling practices. A CLI tool should never transmit a user's entire home directory to remote servers without explicit, informed consent and clear user interaction. The bulk transfer of authentication credentials and personal files represents a severe security vulnerability.
xAI has not yet publicly commented on the scope of the incident, remediation steps, or whether other users are affected. Developers should immediately audit their system access if they used this tool and consider rotating exposed credentials.
Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.