Tuesday, September 15, 2026

xAI Developer Accidentally Leaks API Key Granting Access to SpaceX, Tesla, and X LLMs

An employee at Elon Musk’s artificial intelligence venture, xAI, inadvertently disclosed a sensitive API key on GitHub, potentially exposing proprietary large language models (LLMs) linked to SpaceX, Tesla, and Twitter/X.

Cybersecurity specialists estimate the leak remained active for two months, offering outsiders the capability to access and query highly confidential AI systems engineered with internal data from Musk’s flagship companies.

The leak first surfaced when Philippe Caturegli, “chief hacking officer” at Seralys, flagged the compromised credentials for an xAI application programming interface in a GitHub repository belonging to a technical staffer at xAI.

Caturegli’s announcement on LinkedIn swiftly caught the eye of GitGuardian, a firm specializing in automated detection of exposed secrets in codebases.

Eric Fourrier, co-founder of GitGuardian, told KrebsOnSecurity that the exposed API key had access to at least 60 fine-tuned LLMs, including unreleased and private models.

These encompassed evolving versions of xAI’s Grok chatbot, as well as specialized models fine-tuned on SpaceX and Tesla data, such as “grok-spacex-2024-11-04” and “tweet-rejector”.

“The credentials could be used to access the xAI API with all privileges granted to the original user,” GitGuardian explained.

“These included not only public Grok models, but also cutting-edge, unreleased, and internal tools never meant for external eyes.”

Despite an automated alert sent to the xAI employee on March 2, the credentials remained valid and active until at least April 30, when GitGuardian escalated the issue directly to xAI’s security team.

Just hours later, the offending GitHub repository was quietly taken down.

Carole Winqwist, GitGuardian’s chief marketing officer, warned that adversaries with such access could manipulate or sabotage these language models for malicious purposes, including prompt injection attacks or even planting code within the AI’s operational supply chain.

“Free access to private LLMs is a recipe for disaster,” Winqwist emphasized.

The leak also highlights growing concerns about the integration of sensitive data with AI tools.

Recent reports indicate Musk’s Department of Government Efficiency (DOGE) and other agencies are feeding federal data into AI, raising questions about broader security risks.

While there is no direct evidence that federal or user data was breached through the exposed API key, Caturegli underscores the seriousness of the incident: “Long-lived credential exposures like this reveal weak key management and poor internal monitoring, raising alarms about operational security at some of the world’s most valuable tech companies.”

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a...

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

A Casbaneiro banking Trojan campaign targeting users across Latin...

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

Related Articles

Recent News