xAI's Grok Build exposed developers' secrets through cloud uploads

xAI's coding assistant was transmitting complete Git repositories—including hardcoded credentials, API keys, and private data—to its servers without explicit developer consent or clear disclosure. A security researcher's wire-level analysis confirmed the practice was happening at scale, creating a direct pipeline of sensitive information from thousands of developers' machines into a third-party AI vendor's infrastructure. The incident exposes the gap between how developers assume local tools operate and the actual data collection practices of AI-powered development platforms, and raises questions about how tightly integrated coding assistants should be with cloud infrastructure.