A staffer at the U.S. Department of Government Efficiency accidentally committed code containing a valid xAI API key to a public GitHub repository on July 13, 2026, exposing access to at least 52 of xAI’s large language models. Security researchers warned the exposed key could have enabled convincing phishing content, fake official communications, or disinformation at scale had it been exploited before discovery. It was the second such xAI credential exposure reported in 2026, after an earlier internal API key tied to systems associated with Musk-affiliated companies sat exposed on GitHub for roughly two months.