Source: The Next Web
xAI's coding assistant was transmitting complete Git repositories—including hardcoded credentials, API keys, and private data—to its servers without explicit developer consent or clear disclosure. A security researcher's wire-level analysis confirmed the practice was happening at scale, creating a direct pipeline of sensitive information from thousands of developers' machines into a third-party AI vendor's infrastructure. The incident exposes the gap between how developers assume local tools operate and the actual data collection practices of AI-powered development platforms, and raises questions about how tightly integrated coding assistants should be with cloud infrastructure.