5 Sources
[1]
DOGE staffer with access to Americans' personal data leaked private xAI API key
A DOGE staffer with access to the private information on millions of Americans held by the U.S. government reportedly exposed a private API key used for interacting with Elon Musk's xAI chatbot. Independent security journalist Brian Krebs reports that Marko Elez, a special government employee who
[2]
A leaked xAI security key could put your data at risk -- here's what happened
A federal government employee has reportedly leaked a sensitive API key linked to Elon Musk's xAI platform -- and it could have serious implications for both national security and the future of AI development. According to a report from TechRadar, Marko Elez, a 25-year-old software developer with
[3]
DOGE staffer reportedly published secret xAI key to dozens of AI models
Marko Elez keeps coming up in news headlines and it's never for good reasons. Credit: Andrey Rudakov/Bloomberg via Getty Images Five months after DOGE staffer Marko Elez resigned from the agency over racist social media posts, he's not only back at DOGE, but back in the news for another
[4]
DOGE employee leaks private xAI API key from sensitive database
A staffer with access to the personal data of millions of Americans has apparently leaked the API Key to at least four dozen LLMs developed by artificial intelligence company xAI, including X's (formerly Twitter) own chatbot Grok. Security expert Brian Krebs revealed Marko Elez, an employee at
[5]
An Elon Musk ally gave away the keys to Grok's AI brain
Just months after returning to government service following a controversial resignation, Department of Government Efficiency (DOGE) staffer Marko Elez is back in the spotlight -- this time for exposing a sensitive API key tied to Elon Musk's artificial intelligence company, xAI. On Sunday, Elez
Share
Copy Link
A Department of Government Efficiency (DOGE) employee accidentally exposed a private API key for xAI's language models, including Grok, on GitHub. This incident raises serious questions about data security practices in government agencies and the increasing integration of private AI technologies in public sector operations.
In a significant security breach, Marko Elez, a staffer at the Department of Government Efficiency (DOGE), accidentally leaked a private API key granting access to at least 52 large language models (LLMs) developed by xAI, Elon Musk's artificial intelligence company
1
2
. The exposed models include the latest version of Grok, a GPT-4-class model powering some of Musk's most advanced AI services2
.
Source: Tom's Guide
The leak occurred when Elez, a 25-year-old software developer, uploaded a script titled "agent.py" to GitHub, which contained the sensitive API key
2
. This key provided backend access to xAI's model suite, including Grok-4, without any apparent usage restrictions2
. The exposed credentials remained active for a concerning period, raising major questions about access control and data security2
.Security expert Brian Krebs revealed that Elez had access to sensitive databases at various U.S. government agencies, including the Social Security Administration, Department of Justice, and Treasury Department
4
. This access was part of DOGE's work in 'streamlining' these departments to increase efficiency4
.The incident has sparked concerns about the handling of sensitive information within government agencies. Philippe Caturegli, CTO at cybersecurity firm Seralys, stated, "If a developer can't keep an API key private, it raises questions about how they're handling far more sensitive government information behind closed doors"
2
4
.This is not the first time internal xAI APIs have been leaked. Earlier in 2025, LLMs made for Musk's other organizations, including SpaceX, Tesla, and Twitter/X, were also exposed
4
. These repeated lapses point to deeper issues in operational security and highlight the blurry lines between Musk's companies and the government agencies now increasingly relying on his infrastructure5
.Marko Elez has been involved in previous controversies. He resigned from DOGE earlier due to racist social media posts but returned to the agency within weeks, aided by lobbying from Vice President J.D. Vance
5
. Since his return, Elez has worked across multiple high-level agencies, holding access to sensitive databases involving immigration systems, financial records, and national security operations5
.
Source: TechCrunch
Related Stories
The leak comes at a critical time, just days after the Department of Defense awarded a contract worth up to $200 million for Grok, despite recent controversies surrounding the chatbot
5
. This incident underscores the growing entanglement between Silicon Valley and Washington, raising questions about vetting, cybersecurity hygiene, and potential conflicts of interest5
.
Source: Quartz
As of the latest reports, xAI has not revoked the exposed key, and neither DOGE nor Elez has issued a public response
5
. The continued accessibility of the leaked API key remains a security concern, potentially allowing unauthorized access to powerful language models2
4
.This incident serves as a stark reminder of the need for stringent security measures and oversight in the rapidly evolving landscape of AI technology, especially when it intersects with government operations and sensitive data.
Summarized by
Navi
23 May 2025•Policy and Regulation

22 Feb 2025•Policy and Regulation

08 Apr 2025•Technology

1
Technology

2
Policy and Regulation

3
Technology
