Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› xAI API Key Leak 2025: How a Developer’s…
Breach analysis Incident: 1 May 2025

xAI API Key Leak 2025: How a Developer’s Public GitHub Commit Exposed Private Grok Models for Two Months

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
Attack route: Leaked secret Identities: API key
On this page

On 2 March 2025 a member of xAI's technical staff committed an xAI API key to a public GitHub repository in an .env file. GitGuardian's automated scanning spotted it the same day and emailed the developer, but the key stayed live. About two months later Philippe Caturegli of the consultancy Seralys publicised the exposure on LinkedIn. GitGuardian then confirmed the key still worked and could reach public, unreleased and private Grok models, including ones named "grok-spacex-2024-11-04" and "tweet-rejector". KrebsOnSecurity, reporting on 1 May 2025, said the key gave access to at least 60 fine-tuned and private models that appear to be built on data from SpaceX, Tesla and X. GitGuardian alerted xAI's security team on 30 April. xAI first pointed it to its bug bounty programme, then removed the repository and revoked the key within hours, about 59 days after the first alert. No misuse of the key has been reported.

Key takeaways

  • An xAI developer leaked an xAI API key in a public GitHub repository on 2 March 2025, according to GitGuardian; the key remained valid until 30 April or 1 May 2025.
  • The key could reach public Grok models and unreleased, development and private models, at least 60 in all according to KrebsOnSecurity, some apparently fine-tuned for SpaceX and X.
  • GitGuardian's automated email to the developer on 2 March did not get the key revoked. It took a public LinkedIn post and a direct report to xAI's security team.
  • No misuse of the key has been reported, and Caturegli told KrebsOnSecurity there was no indication it could reach federal government or user data.
  • The identity lesson: a personal developer key with access to private models is a production credential, and an alert that reaches only the developer is not a revocation process.

At a glance

OrganisationxAI (developer of the Grok models)
WhenKey committed and first flagged 2 March 2025; reported to xAI 30 April 2025; revoked within hours; made public by KrebsOnSecurity 1 May 2025
AttackerNone known. Found by GitGuardian's automated scanning and publicised by Philippe Caturegli of Seralys
Entry pointAn API key committed in an .env file to a public GitHub repository by an xAI technical staff member
Identities abusedAn xAI API key with access to public, unreleased, development and private Grok models
ImpactAbout two months of public exposure of access to at least 60 private and fine-tuned models; no confirmed misuse, and xAI did not comment
CategoryNHI, LLM / AI platform. Incident class: exposure, no confirmed misuse (live API key in a public repository, validated by researchers)

What happened

GitGuardian runs automated scanning of public GitHub commits for secrets. On 2 March 2025 it detected an xAI API key in an .env file committed to a public repository and, as it does for every detection, emailed the commit author. The author's address was on the x.ai domain. GitGuardian says it did not investigate further at the time. KrebsOnSecurity later described the developer as a 28-year-old member of xAI's technical staff, without naming them.

About two months later Philippe Caturegli, "chief hacking officer" at the consultancy Seralys, posted on LinkedIn that he had obtained an xAI API key from a public repository, and tagged GitGuardian. GitGuardian checked and found the key was still valid. It could list public models such as grok-2-1212, an unreleased model (grok-2.5V), a development model (research-grok-2p5v-1018) and private models including tweet-rejector and grok-spacex-2024-11-04. KrebsOnSecurity reported that the key had access to at least 60 fine-tuned and private models. GitGuardian's Eric Fourrier told Krebs: "I definitely don't think a Grok model that's fine-tuned on SpaceX data is intended to be exposed publicly." Caturegli said: "This kind of long-lived credential exposure highlights weak key management and insufficient internal monitoring."

GitGuardian chose not to explore the access further and instead emailed xAI's safety address at 11:00 EST on 30 April 2025. About 12 hours later xAI replied: "would you please submit this to xAI's Bug Bounty Program on HackerOne?" A few hours after that, the repository disappeared from GitHub and the key was revoked, without any update to GitGuardian. KrebsOnSecurity published on 1 May; xAI and the developer did not respond to its requests for comment. In its own write-up on 7 May, GitGuardian criticised the lack of a security.txt file on xAI's site and the routing of an urgent leak report through a bug bounty platform.

No misuse of the key has been reported. Caturegli told KrebsOnSecurity there was no indication that federal government or user data could be reached through it. The concern is what the models themselves might reveal. GitGuardian argued they could contain knowledge of X, Tesla or SpaceX intellectual property, and that free access to private models invites prompt injection and tampering.

Timeline

DateEvent
2 March 2025An xAI developer commits an API key to a public GitHub repository; GitGuardian detects it and emails the developer.
April 2025Philippe Caturegli publicises the exposed key on LinkedIn and tags GitGuardian.
30 April 2025GitGuardian reports the still-valid key to xAI's security team; about 12 hours later xAI asks for a HackerOne report, and within a few more hours the repository is removed and the key revoked.
1 May 2025KrebsOnSecurity publishes the story.
7 May 2025GitGuardian publishes its account of the disclosure.

How it happened: the identity attack path

  1. A broad key on a developer laptop. A staff member held an API key that could reach xAI's private and unreleased models, not just public ones.
  2. Committed to a public repository. The key went to GitHub in an .env file, where automated scanners and anyone else could read it.
  3. Alert without action. GitGuardian's same-day email to the developer did not lead to revocation, and nothing on xAI's side detected the exposure.
  4. Two months of exposure. The key stayed valid for 59 days, from 2 March to 30 April 2025, until outside researchers escalated it directly to xAI.
  5. Revoked after escalation. xAI removed the repository and revoked the key within hours of the direct report.

Impact

  • Exposure: an xAI API key with access to at least 60 private and fine-tuned models was publicly readable for about two months, according to KrebsOnSecurity and GitGuardian.
  • Misuse: no confirmed misuse. xAI did not comment, and neither researcher reported evidence that anyone else used the key.
  • Potential: querying unreleased and private models that may encode proprietary information from SpaceX, Tesla and X, and running up costs on xAI's account.
  • Process: the incident exposed gaps in xAI's security contact and triage, which GitGuardian criticised publicly.

What this means for NHI and AI agent security

AI provider keys are a growing class of non-human identity, and their blast radius is unusual. A model key can do more than spend money: it can expose the behaviour, and possibly the training data, of private models. This key belonged to an AI company itself and reached models that were never meant to be public. It is a reminder that the most sensitive keys are often the ones held by the provider's own developers, who have access to everything in development.

The exposure is ordinary; what made it last was the response. An automated alert went to one person's inbox, and nothing else happened for two months. Secret detection only works when it is tied to an owner and a revocation process that runs whether or not the developer reads their email. Our LLMjacking Guide and API Key Management Guide cover scoping, ownership and rotation for model provider keys, and the Hugging Face token exposure shows the same pattern across many AI organisations.

Recommendations

  • Revoke exposed keys automatically. When a key appears in a public repository, revoke it and issue a new one without waiting for the developer to respond. See our Leaked Credential Response Playbook.
  • Scope developer keys away from private models. Give developers keys limited to the models and environments they need, and keep access to unreleased models behind separate, short-lived credentials. See our LLMjacking Guide.
  • Route secret alerts to the security team. Make sure secret-scanning alerts for company domains reach a monitored queue with an owner, not just the committer. See our API Key Management Guide.
  • Keep .env files out of repositories. Use pre-commit hooks and ignore rules to stop environment files being committed, and load secrets from a secrets manager instead. See our Secrets Management Guide.
  • Publish a clear security contact. Provide a security.txt file and accept urgent credential leak reports directly, outside any bug bounty process.

Frequently asked questions

What happened in the xAI API key leak?

An xAI technical staff member committed an API key to a public GitHub repository on 2 March 2025. The key could reach public, unreleased and private Grok models, at least 60 in all according to KrebsOnSecurity, and stayed valid until GitGuardian reported it to xAI on 30 April 2025.

Was the leaked xAI key misused?

No misuse has been reported. GitGuardian validated the key and chose not to explore further, and Caturegli told KrebsOnSecurity there was no indication that government or user data could be reached. xAI did not comment publicly.

How long was the xAI API key exposed?

About two months. GitGuardian first detected and reported the key to the developer on 2 March 2025, and it was revoked within hours of GitGuardian's report to xAI's security team on 30 April 2025, 59 days later.

Hugging Face API tokens exposure 2023 · Microsoft Azure OpenAI abuse 2025 · Home Depot token exposure 2025 · LLMjacking Guide · API Key Management Guide

How NHI Mgmt Group can help

AI provider keys are multiplying across developer machines, notebooks and repositories, often with far more access than their owners need. We help teams find them, give each one an owner and build revocation that works when a key leaks. See our NHI Foundation Level Training Course.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org