xAI open-sources Grok Build under Apache 2.0 (xai-org/grok-build, almost entirely Rust, targeting Grok 4.5) and resets quotas on every account at the same time. Background: on 10 July a security researcher disclosed that early versions of the CLI uploaded entire Git repositories — commit history and secrets in .env included — to a Google Cloud Storage bucket, and the privacy switch did not stop it. If you ran the CLI in a repo containing secrets before 13 July, treat those credentials as leaked and rotate them.
Original text +
xAI 用 Apache 2.0 开源 Grok Build(xai-org/grok-build,几乎全是 Rust,面向 Grok 4.5),同时重置了所有账号的额度。 背景:7 月 10 日有安全研究者披露,早期版本的 CLI 会把整个 Git 仓库(含提交历史和 .env 里的密钥)上传到一个 Google Cloud Storage 存储桶,而且隐私开关拦不住。7 月 13 日之前在含密钥的仓库里跑过 CLI 的,应该把那些凭证当作已泄露来轮换。
The provider wiped usage directly — nothing for you to do.
// CONTEXT
- 50 days after the previous reset · 2026-05-26
- The next reset came 29 days later · 2026-08-12
- Most recent Grok record: 2026-09-05
- Average gap 34.3d · longest 50d · 0% of past waits were shorter than this one