DOGE Staffer Leaks xAI's Private API Key, Raising Concerns Over Government Data Security

5 Sources

Share

A Department of Government Efficiency (DOGE) employee accidentally exposed a private API key for xAI's language models, including Grok, on GitHub. This incident raises serious questions about data security practices in government agencies and the increasing integration of private AI technologies in public sector operations.

DOGE Staffer Exposes xAI's Private API Key

In a significant security breach, Marko Elez, a staffer at the Department of Government Efficiency (DOGE), accidentally leaked a private API key granting access to at least 52 large language models (LLMs) developed by xAI, Elon Musk's artificial intelligence company

1

2

. The exposed models include the latest version of Grok, a GPT-4-class model powering some of Musk's most advanced AI services

2

.

Source: Tom's Guide

Source: Tom's Guide

The Leak and Its Implications

The leak occurred when Elez, a 25-year-old software developer, uploaded a script titled "agent.py" to GitHub, which contained the sensitive API key

2

. This key provided backend access to xAI's model suite, including Grok-4, without any apparent usage restrictions

2

. The exposed credentials remained active for a concerning period, raising major questions about access control and data security

2

.

Security expert Brian Krebs revealed that Elez had access to sensitive databases at various U.S. government agencies, including the Social Security Administration, Department of Justice, and Treasury Department

4

. This access was part of DOGE's work in 'streamlining' these departments to increase efficiency

4

.

Broader Security Concerns

The incident has sparked concerns about the handling of sensitive information within government agencies. Philippe Caturegli, CTO at cybersecurity firm Seralys, stated, "If a developer can't keep an API key private, it raises questions about how they're handling far more sensitive government information behind closed doors"

2

4

.

This is not the first time internal xAI APIs have been leaked. Earlier in 2025, LLMs made for Musk's other organizations, including SpaceX, Tesla, and Twitter/X, were also exposed

4

. These repeated lapses point to deeper issues in operational security and highlight the blurry lines between Musk's companies and the government agencies now increasingly relying on his infrastructure

5

.

Elez's Controversial Background

Marko Elez has been involved in previous controversies. He resigned from DOGE earlier due to racist social media posts but returned to the agency within weeks, aided by lobbying from Vice President J.D. Vance

5

. Since his return, Elez has worked across multiple high-level agencies, holding access to sensitive databases involving immigration systems, financial records, and national security operations

5

.

Source: TechCrunch

Source: TechCrunch

Implications for AI and Government Collaboration

The leak comes at a critical time, just days after the Department of Defense awarded a contract worth up to $200 million for Grok, despite recent controversies surrounding the chatbot

5

. This incident underscores the growing entanglement between Silicon Valley and Washington, raising questions about vetting, cybersecurity hygiene, and potential conflicts of interest

5

.

Ongoing Concerns and Lack of Response

Source: Quartz

Source: Quartz

As of the latest reports, xAI has not revoked the exposed key, and neither DOGE nor Elez has issued a public response

5

. The continued accessibility of the leaked API key remains a security concern, potentially allowing unauthorized access to powerful language models

2

4

.

This incident serves as a stark reminder of the need for stringent security measures and oversight in the rapidly evolving landscape of AI technology, especially when it intersects with government operations and sensitive data.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo