Fetching from the wire…
Public story · 2026-07-14 · high
Turning off the Improve the model toggle didn't stop the uploads, and xAI's fix arrived quietly, undocumented, a day later.
Why now: There's still no public advisory from xAI, so the only account of what Grok Build collected and when the fix landed is cereblab's mitmproxy trace.
Grok Build CLI v0.2.93 uploaded whole tracked repositories to a Google Cloud Storage bucket during ordinary coding sessions, per a Hacker News post from researcher cereblab. The uploads included full Git history.
On a 12GB test repo, cereblab measured 5.1GB of uploads split across 73 chunks, against roughly 192KB of actual model traffic. That's more than 26,000 times as much data leaving the machine as the model itself needed to answer a prompt.
The bucket, named grok-code-session-traces, also received a file the agent had been explicitly instructed not to read. Whatever the Improve the model setting is supposed to gate, it didn't cover that file.
Turning the toggle off didn't help either. The Grok Build server kept returning trace_upload_enabled:true no matter the local setting. Switching the feature off in the CLI had no effect on what actually left the repo.
xAI's fix arrived about a day after the findings went up: a hidden disable_codebase_upload flag, undocumented anywhere. The v0.2.98 changelog doesn't mention it. Cereblab's post doesn't say whether xAI told anyone whose code had already passed through the bucket before that flag existed.
Whether disable_codebase_upload actually blocks the behavior is untested in public. The same mitmproxy setup cereblab used to catch the original uploads would show whether the new flag works.
Each link below shares sources, entities, or timing with this story.
xAI launched Grok 4.5 and Grok Build on July 8, trained partly on Cursor developer-session data. The numbers are loud: 83.3% on Terminal-Bench 2.1, 64.7% on SWE-Bench Pro, priced at $2/$6 per million tokens. On a single coding task that works out to roughly $2.49 versus $11.80...
I check Product Hunt maybe once a week and usually regret it. Today's board is worth reading as market structure. The July 30 leaderboard: SKI at 277 upvotes (free voice input for Claude Code and Codex). AI Search Console at 249 (prompt analytics and citation mapping). Memmy A...
For a year the pitch was "one great AI pair programmer." That's over. stablyai/orca, a YC-backed open-source "agent development environment," blew past 12,500 GitHub stars by running Claude Code, Codex, Cursor, Grok, OpenCode, Pi, and 30+ other CLI agents side by side, each in...
xAI launched Grok Build on May 14. With that, every major AI lab now ships a coding agent that lives in your terminal. The competition isn't "can we build one" anymore. That question is settled. The lineup: Anthropic has Claude Code. OpenAI has Codex CLI. Google has Gemini CLI...
This one hit 395 points and 548 comments on Hacker News for good reason. A developer was running Cursor with Claude Opus 4.6 as the backing model. The agent made a single Railway API call that deleted the production database AND all volume-level backups. Nine seconds. Everythi...
The IDE market is fragmenting, and this week drew the sharpest lines yet. Cursor 3 launched as a rebuilt agent-orchestration platform in Rust and TypeScript, replacing the VS Code fork with an Agents Window for dispatching and monitoring multiple AI coding agents. Anysphere hi...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.