Skip to content
ai tools

Grok CLI Was Spyware. Here's The Proof.

xAI's coding assistant was caught secretly uploading entire home directories, including SSH keys and password managers. This wasn't a bug; it was a feature that ignored user commands and privacy settings.

Nora Vance
Grok CLI Was Spyware. Here's The Proof.

More Than Code: Grok Grabbed Your Secrets

Security researcher Cereblab uncovered a disturbing truth about xAI’s Grok CLI. The tool, version 0.2.93, was caught uploading entire user directories, including highly sensitive data like SSH keys, password manager databases, and personal photos. This happened despite explicit instructions for Grok not to read any files, such as "Reply OK and do not look at any files."

This data exfiltration reached a staggering scale. For a task needing only 192 kilobytes of information, Grok CLI sent a whopping 5.1 gigabytes of data to a Google Cloud bucket, specifically named grok-code-session-traces. This upload volume was roughly 27,800 times larger than necessary, far exceeding any reasonable requirement.

Most concerning, this massive data dump occurred with the "Improve the model" privacy toggle disabled within the CLI's settings. Such behavior demonstrates a profound disregard for user consent and privacy controls, fundamentally betraying trust. Unlike competitors such as Claude Code or Gemini, Grok was the only one exhibiting this invasive data collection.

No Excuses: The Industry Reacts to xAI's Breach

Unlike its competitors, Grok CLI was a dangerous outlier. While tools like Claude Code, OpenAI’s Codex CLI, and Google’s Gemini CLI transmitted only the specific files they actually read, keeping user data secure, Grok ignored explicit instructions. It uploaded entire directories, including sensitive SSH keys, password managers, and photos, even for tasks requiring just a single file, sometimes sending 5.1 gigabytes for a 192-kilobyte job.

This alarming behavior drew sharp industry condemnation. Gergely Orosz, author of The Pragmatic Engineer, publicly stated no "sensible company" would use the tool after this incident. OpenAI CEO Sam Altman reportedly found the situation "concerning," highlighting the profound security and trust implications of xAI’s breach.

xAI scrambled to contain the damage. A server-side kill switch was hastily deployed on July 13, 2026, disabling the pervasive upload functionality. Elon Musk Musk then publicly promised that all previously harvested user data would be "completely and utterly deleted." Two days later, on July 15, 2026, xAI also open-sourced the Grok CLI, attempting to restore some measure of transparency after the spyware revelation.

Transparency Theater: Is Grok's 'Fix' Real?

After Cereblab's damning findings went viral, xAI scrambled to contain the damage. On July 15, 2026, the company open-sourced the Grok Build CLI, a move presented as a commitment to transparency. This was less a proactive measure and more a reactive gesture, desperately trying to polish a tarnished reputation.

xAI also introduced a /privacy command and a Zero Data Retention (ZDR) policy. The crucial flaw: these were server-side toggles, meaning your sensitive data, including SSH keys and password manager files, still transmitted to xAI’s servers. Users were left to trust xAI to discard their data after receipt, a precarious position given the prior unauthorized uploads.

Even with these "fixes," the underlying upload code initially remained in the Grok CLI binary, controlled by a remote flag. This raised serious questions about whether the invasive functionality could be silently re-enabled at xAI's discretion. For more details on the initial findings, see xAI's Grok Build CLI Caught Uploading Entire Codebases to Google Cloud Without Consent. Elon Musk Musk's promise that all data was "completely and utterly deleted" felt like cold comfort after this transparency theater.

Enjoying this? Get one like it in your inbox each morning.

one email a day · unsubscribe in two clicks · no third-party tracking

Your Next Move: Rotate Keys, Reconsider Tools

Anyone who used Grok Build CLI before xAI's server-side "kill switch" on July 13, 2026, must assume their credentials are compromised. Immediately rotate all SSH keys, API keys, and any other secrets exposed in your home directory or Git repositories. Researcher Cereblab's wire-level analysis proved Grok CLI uploaded entire directories, including sensitive .env files and password managers, even when told not to.

This incident creates a profound and lasting trust deficit. While xAI might tout Grok's performance on benchmarks like SWE-bench, such metrics become utterly meaningless if developers cannot trust the tool with their fundamental source code. The revelation that Grok was a dangerous outlier, transmitting full repositories while competitors like Claude Code and Gemini sent only needed files, makes any promise of data deletion ring hollow.

Grok's unauthorized 5.1 gigabyte upload for a mere 192 kilobyte task—a staggering 27,800 times the necessary data—serves as a stark warning. Relying on closed-source, beta-stage AI tools, especially those interacting with sensitive development environments, introduces unacceptable risks. Client-side transparency and granular control are not optional features; they are absolute necessities for any AI tool interacting with your codebase, safeguarding against future spyware and ensuring true client-side transparency.

Frequently Asked Questions

What data did the Grok CLI upload without consent?

The Grok CLI (version 0.2.93) uploaded entire user home directories and Git repositories. This included sensitive data like SSH keys, password manager databases, .env files with API keys, photos, and documents.

How did xAI respond to the Grok CLI privacy scandal?

After the issue went viral, xAI implemented a server-side 'kill switch' to stop the uploads, Elon Musk promised to delete the data, and the company open-sourced the Grok CLI under an Apache 2.0 license to improve transparency.

Is the Grok CLI safe to use now?

xAI has disabled the functionality and introduced a /privacy command. However, the command only tells xAI's servers to discard data upon receipt; it doesn't prevent the client from sending it. Trust is a significant concern, but community audits of the now open-source code may help verify its safety.

What should I do if I used the Grok CLI before July 13th, 2026?

Security experts strongly advise you to rotate all credentials that the tool could have possibly accessed. This includes SSH keys, API keys from .env files, and any passwords stored in a database that was in your home directory or a scanned repository.

Found this useful? Share it.

For builders

Want Stork to write one of these about your product?

Send us a URL. We use the product, form a view, and publish what we actually think — in 8 languages, labeled Sponsored, with no copy approval on your side. That last part is what makes it worth quoting.

See how it works$500 · AI tools & software only