News

Public · Published

Grok leaks user chats via encrypted webpage trick, 11 weeks after xAI warned

Adversa AI reported that Grok is still exposing users' names, locations, and complete chat histories to attackers who hide encrypted commands on a web page, and xAI has not yet released a fix.

Published:

Updated:

What happened

Adversa AI reported that Grok is still exposing users’ names, locations, and complete chat histories to attackers who hide encrypted commands on a web page, and xAI has not yet released a fix.

Confirmed

Global impact / market context

The leak puts personal data at risk, which can erode user trust, trigger investigations by privacy regulators, and drive users to competing services, potentially lowering Grok’s revenue and hurting xAI’s ability to raise future funding.

Analyst inference

Amid rapid growth of AI chatbots, recent security breaches have heightened investor focus on data protection, prompting a shift toward firms with robust safeguards and influencing valuation multiples across the generative‑AI sector in the near term.

Analyst inference

What to watch

  1. Watch for xAI’s announcement of a security patch to stop the encrypted‑webpage exploit, because fixing it could restore user confidence and limit further data loss. Analyst inference
  2. Watch for any follow‑up statements from Adversa AI confirming additional leak vectors, as new details could broaden the scope of affected user data. Analyst inference
  3. Watch competitor AI chatbot providers as they may emphasize privacy features in marketing, potentially pulling users away from Grok if the leak remains unpatched. Analyst inference

Evidence