cd /news/ai-tools/musk-s-coding-agent-uploaded-27800x-… · home topics ai-tools article
[ARTICLE · art-62190] src=pub.towardsai.net ↗ pub= topic=ai-tools verified=true sentiment=↓ negative

Musk's Coding Agent Uploaded 27,800x More Data Than the Task Needed — Your Whole Repo, Secrets…

A security researcher known as cereblab found that xAI's Grok Build coding agent CLI 0.2.93 uploaded 5.10 GiB of data to a Google Cloud Storage bucket named `grok-code-session-traces` when only 192 KB was needed for a task — a 27,800x excess. The upload included entire home directories with SSH keys and password-manager databases, prompting Elon Musk to promise deletion of all previously uploaded user data. The incident, which hit the front page of Hacker News on July 14, highlights the risk of coding agents exfiltrating sensitive data without user knowledge.

read1 min views58 publishedJul 16, 2026
Musk's Coding Agent Uploaded 27,800x More Data Than the Task Needed — Your Whole Repo, Secrets…
Image: Pub (auto-discovered)

Member-only story

The model turn needed 192 KB. The storage channel moved 5.10 GiB. That is a 27,800x gap between what xAI’s Grok Build coding agent needed to answer a prompt and what actually left the researcher’s machine — and the destination was a Google Cloud Storage bucket named grok-code-session-traces

that no setup doc ever mentioned.

On July 12, a security researcher publishing as cereblab dropped a wire-level analysis of Grok Build CLI 0.2.93. By July 14 it was on the front page of Hacker News, other users were reporting that their entire home directories — SSH keys and password-manager databases included — had been swept up, and Elon Musk was personally promising that “all user data that was uploaded to xAI before now will be completely and utterly deleted. Zero anything whatsoever will remain.”

I spent yesterday reading the full capture log and reproducing the audit methodology against my own tools. This article covers what was actually proven (which is narrower and scarier than the headlines), and then the part that matters for you: how to wire-audit any coding agent you run — Claude Code, Codex, Cursor, or Grok — in about 15 minutes with mitmproxy. Because the uncomfortable lesson of this story is that the only person who checked was one anonymous…

── more in #ai-tools 4 stories · sorted by recency
── more on @xai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/musk-s-coding-agent-…] indexed:0 read:1min 2026-07-16 ·