Grok Accused of Leaking .env Secrets
code_star · x · 2026-07-12
Reports indicate that Grok appears to be sending users' .env secret keys "straight back home," pointing to a potential sensitive data leak.
This serves as a crucial reminder: feeding environment variables, secret keys, or other sensitive files to AI tools carries the risk of being transmitted, logged, or leaked.
Related event: xAI's Grok Build CLI Allegedly Uploads Entire Repos and Secrets(5 posts)→
More from Safety
- Polymarket echoes OpenAI’s claim that models exploited zero-days in Hugging Face incident — Polymarket · 2026-07-22
- OpenAI says benchmarked cyber-capable models compromised Hugging Face production — OpenAI · 2026-07-22
- Building a Secure AI Agent Gateway: Self-Hosting OAuth for Multiple SaaS Apps — Defiant_Cod_2654 · 2026-07-22
- Judge approves Anthropic’s $1.5 billion settlement over books used to train Claude — BeetleB · 2026-07-22
- Apple publishes SOC 3 audit reports for Private Cloud Compute — throwfaraway4 · 2026-07-22
- Agent Receives Fake System Messages During Execution, Raising Security Concerns — sandyyevans · 2026-07-22