Latest Breaking News
Showing Original Post only (View all)DOGE staffer with access to Americans' personal data leaked private xAI API key [View all]
Source: TechCrunch
A DOGE staffer with access to the private information on millions of Americans held by the U.S. government reportedly exposed a private API key used for interacting with Elon Musks xAI chatbot.
Independent security journalist Brian Krebs reports that Marko Elez, a special government employee who in recent months has worked on sensitive systems at the U.S. Treasury, the Social Security Administration, and Homeland Security, recently published code to his GitHub containing the private key. The key allowed access to dozens of models developed by xAI, including Grok.
Philippe Caturegli, founder of consultancy firm Seralys, alerted Elez to the leak earlier this week. Elez removed the key from his GitHub but the key itself was not revoked, allowing continued access to the AI models.
-snip-
Read more: https://techcrunch.com/2025/07/15/doge-staffer-with-access-to-americans-personal-data-leaked-private-xai-api-key/
More, from KrebsOnSecurity.com:
https://krebsonsecurity.com/2025/07/doge-denizen-marko-elez-leaked-api-key-for-xai/
On July 13, Mr. Elez committed a code script to GitHub called agent.py that included a private application programming interface (API) key for xAI. The inclusion of the private key was first flagged by GitGuardian, a company that specializes in detecting and remediating exposed secrets in public and proprietary environments. GitGuardians systems constantly scan GitHub and other code repositories for exposed API keys, and fire off automated alerts to affected users.
Philippe Caturegli, chief hacking officer at the security consultancy Seralys, said the exposed API key allowed access to at least 52 different LLMs used by xAI. The most recent LLM in the list was called grok-4-0709 and was created on July 9, 2025.
-snip-
If a developer cant keep an API key private, it raises questions about how theyre handling far more sensitive government information behind closed doors, Caturegli told KrebsOnSecurity.
-snip-
The article continues with reminders that at the Treasury Department, Elez violated agency policies by sending unencrypted personal information. He wasn't fired for that, but resigned after news stories about racist and pro-eugenics social media posts. Then Peter Thiel lackey JD Vance convinced Trump he should be rehired, and he's since worked at a number of departments:
Social Security Administration
Department of Labor
Customs and Border Protection
ICE
Department of Justice
