DOGE employee leaks private xAI API key from sensitive database
- A security researcher has uncovered a worrying API key leak
- The leak reportedly comes from DOGE staffer Marko Elez
- This is not the first security issue originating from DOGE
A staffer with access to the personal data of millions of Americans has apparently leaked the API Key to at least four dozen LLMs developed by artificial intelligence company xAI, including X’s (formerly Twitter) own chatbot Grok.
Security expert Brian Krebs revealed Marko Elez, an employee at Elon Musk’s Department of Government Efficiency, had access to sensitive databases at the US Social Security Administration, Justice, and Treasury departments as part of DOGE’s work in ‘streamlining’ the departments to increase efficiency.
Ironically, researchers recently uncovered that a DOGE worker’s credentials were exposed by infostealing malware, so DOGE’s security record so far is less than impressive.
Grok exposed
A code script was committed to GitHub named ‘agent.py’ that included a private application programming interface (API) key for xAI by Elez. This was first flagged by GitGuardian, a firm which scans GitHub for API secret tokens, database credentials, and certificates – and alerts affected users.
The exposed API key allowed access to at least 52 different LLMs used by xAI, with the most recent being an LLM called ‘grok 4-0709’, created on July 9, 2025 – according to Chief Hacking Officer at security consultancy Seralys, Philippe Caturegli.
Caturegli warned KrebsOnSecurity, “If a developer can’t keep an API key private, it raises questions about how they’re handling far more sensitive government information behind closed doors.”
The code repository that contains the private API key has since been removed after Elez was notified by email of the leak, however, the key still works and has not yet been revoked, so the issue is far from resolved.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
This is not the first time internal xAI APIs have been leaked, with LLMs made for Musk’s other organisations, like SpaceX, Tesla, and Twitter/X exposed earlier in 2025, Krebs confirmed.
“One leak is a mistake,” Caturegli said, “But when the same type of sensitive key gets exposed again and again, it’s not just bad luck, it’s a sign of deeper negligence and a broken security culture.”
You might also like
A security researcher has uncovered a worrying API key leak The leak reportedly comes from DOGE staffer Marko Elez This is not the first security issue originating from DOGE A staffer with access to the personal data of millions of Americans has apparently leaked the API Key to at least…
Recent Posts
- The University of Cambridge says it successfully tested a vaccine with an AI-designed antigen
- MAHA wants to make cotton the new beef tallow
- What do you mean my new smart scale is ‘built for GLP-1 users’?
- What do you mean my new smart scale is ‘built for GLP-1 users’?
- Can AI tell if your script will make a hit film?
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023