Developers say xAI’s Grok Build uploaded entire home directories, exposing sensitive files

Developers say xAI’s Grok Build uploaded entire home directories, exposing sensitive files

N
News Editor
2026-07-13 15:05:24
xAI’s coding tool Grok Build is facing scrutiny after developers on X said it may upload far more local data than expected, including highly sensitive personal files. On July 13, 2026, developer A Green Being said the tool uploaded his entire user home directory to xAI’s servers after he ran it from that location. He said the uploaded data included SSH keys, a password manager database, documents, photos and videos. A screenshot of the user’s unified.json log appeared to show repeated repo_state.upload.start events, with the upload path pointing to “/home/usuario.” The post drew renewed attention to an earlier warning from CyberSatoshi, who had said Grok Build was uploading full repositories, Git history and hidden .env files containing API keys to Google Cloud Platform. The incident has intensified discussion around file-scoping, exclusion rules and execution environment controls in AI coding tools. The source report said developers should avoid running such tools from a root or home directory and instead use sandboxes, Docker containers or restricted user accounts. It also cited a terminal command that users can run to inspect Grok logs for upload activity.
xAIGrok Buildprivacydata leakAI coding toolsdeveloper security

xAI’s Grok Build has come under fire from developers who say the coding tool may upload local data to the cloud without adequately limiting what gets sent.

Developers say xAI’s Grok Build uploaded entire home directories, exposing sensitive files 2

On July 13, 2026, developer A Green Being (@a_green_being) wrote on X that after accidentally running the tool from his home directory, “Grok has uploaded my entire user directory to xAI’s servers. It contains my SSH keys, my password manager database, my documents, photos, videos, everything.”

Log screenshot pointed to the user’s home directory

According to the unified.json log screenshot shared by the user, the system triggered multiple repo_state.upload.start requests, and the upload path pointed directly to the home directory at /home/usuario. Based on the screenshot cited in the report, the uploads covered files stored across that local directory.

The X post said: “Okay, grok has uploaded my entire user directory to xAI’s servers. It contains my SSH keys, my password manager database, my documents, photos, videos, everything.”

Earlier warnings mentioned repositories, Git history and .env files

The post from A Green Being came in response to a prior warning from CyberSatoshi (@XBToshi), who had said Grok Build was quietly uploading entire repositories, Git history and hidden .env files that can contain API keys and other secrets. CyberSatoshi said that data was being sent to Google Cloud Platform, or GCP.

CyberSatoshi had urged developers to inspect local Grok logs to check for possible data exposure. After A Green Being described what happened, CyberSatoshi replied, “You had it worse than me, you ran Grok in your home directory.”

Report urged developers to avoid running the tool from root or home directories

The incident has renewed attention on permission boundaries and data collection practices in AI-assisted development tools. The source report said tools of this kind can create serious security problems if they do not properly exclude files such as those covered by .gitignore or system hidden files.

The report recommended avoiding the use of Grok Build and similar tools from a root directory or a home directory. It also pointed to using isolated sandboxes, Docker containers or restricted user accounts, and cited a command for checking upload activity in Grok logs: cat ~/.grok/logs/unified.json | grep repo_state.upload.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.