Doge Denizen Marko Elez Leaked API Key for XAI

(krebsonsecurity.com)

69 points | by todsacerdoti 6 hours ago ago

25 comments

  • sleazebreeze 6 hours ago

    Nothing to see here. Move right along. I'm sure one or two or a handful of repeated incidents don't represent a trend or potential for future fuck-ups.

    What is DOGE even doing now? Can we get some status reports on what the DOGE employees are doing every week since they're such proponents of radical accountability?

    • burnt-resistor 5 minutes ago

      Destroying things to justify privatization while stealing every detail about us to increase profits and target opponents. Sure, there are HIPAA, secrecy, and confidentiality violations happening but there's no one left to prosecute the criminals when the criminals are the police, COTUS, SCOTUS, and the unitary executive. The only meaningful distinction remaining is patronage vs. outsider.

    • icecreamscoop 3 hours ago

      Officially they are still re-writing the software that runs Social Security. Back in May, they said re-writing >1 millions lines of COBOL would only take a few months.

      https://www.wired.com/story/doge-rebuild-social-security-adm...

      Unofficially, they are the worst people so they are probably doing the worst things you can imagine.

      • jauntywundrkind an hour ago

        Wired also had this recent update, on "DOGE 2.0".

        > But without flashy leadership, DOGE technologists are now quietly cycling into federal agencies, spending days or weeks building products and cutting contracts before cycling out once again. This is all done with little oversight from the White House or the United States DOGE Service (USDS), which these technologists purportedly represent.

    • an hour ago
      [deleted]
    • bix6 3 hours ago

      Just ask Grok with the free key!

      • aspenmayer 2 hours ago

        the sound of one hand clapping (AI generated)

    • 5 hours ago
      [deleted]
  • sashank_1509 6 hours ago

    Jokers, even GitHub auto checks if you push code with a private key.

    • blibble 6 hours ago

      I doubt it has an integration with grok

  • quantified 6 hours ago

    > “If a developer can’t keep an API key private, it raises questions about how they’re handling far more sensitive government information behind closed doors,”

    It raises additional questions. Plenty of questions already unanswered. Seems likely it's been a shitshow.

    • saalweachter 6 hours ago

      Like, "why does this nominal government employee have the API key to XAI"/"why is an active X employee playing such a prominent role in the government"?

      • zdragnar 6 hours ago

        External tech workers have been a thing since at least the catastrophe that was the original ACA launch. That "tech surge" was definitely full of more experienced people than the "smart kids" we see in DOGE though.

        More worrying is that the article points out at time of writing the key was still valid. Why such a high level key was used in an agent script, why it hasn't been rotated (can't be rotated?) and about a dozen other "whys" point to some rather damning practices.

        I get that the idea was to avoid the obscene levels of red tape that can be common in government IT, but the pendulum has clearly swung far, far far too far the other way.

    • JumpCrisscross 5 hours ago

      > It raises additional questions

      Ones we should be ready to prosecute with official resources come ‘26 and ‘28.

      In the meantime, I wouldn’t let him into my country. But the EU will be the EU.

  • optimalsolver 6 hours ago

    This was the "normalize Indian-hate" guy.

    • phendrenad2 3 hours ago

      Very interesting that he had to resign from DOGE over this, yet xAI seemingly welcomed him.

  • epicwynn 4 hours ago

    Just another example showing that power and persistence does not equal competence.

  • fennec-posix 5 hours ago

    Once, I can understand, but twice? come on... And the keys were still valid hours later (according to the article)

  • ada1981 5 hours ago

    I regularly expose my AI api keys in my weekly zoom meetings for our AI Playground :)

    So far no one has taken me up on them.

    Feel free to join as a VIP anytime!

  • waltercool 4 hours ago

    [dead]

  • lbrito 6 hours ago

    These reports seem increasingly irrelevant. There are surely many people that care and are outraged, but that's about it. Tomorrow the news cycle will have something else, and the 20 year olds scrapping their pants at doge will be yesterday's news.

    • esseph 6 hours ago

      XAI key is potentially root into X (social media), and Tesla via grok, yes?

      If so, sounds potentially life threatening.

      NTSB might wanna look into that.

      Edit: DoD is also contracting for $200 million for grok. Yeah, this is bad. https://www.washingtonpost.com/technology/2025/07/14/elon-mu...

      • glaucon 5 hours ago

        > DoD is also contracting for $200 million for grok

        Somewhat to one side but when up to USD800 million is being spent (Grok, is not the only AI shaped snout at the trough) it's depressing to see the vagueness of the supposed uses [1] (in a five line paragraph this is the most specific description of why that need to spend the money ... "to support our warfighters and maintain strategic advantage over our adversaries")

        [1] https://archive.ph/p1ZXR#selection-719.61-719.141

        • esseph 3 hours ago

          There are a lot of classified contracts, services, etc.

      • lbrito 5 hours ago

        That's kind of my point. It is bad And likely no one will be held accountable for it.