An AI Agent via Grok Bot Leaks the Personal Accounts of XMTP's CEO

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Shane Mac, CEO of XMTP Labs, had his savings account balance and his largest expenses of the month exposed in an internal Slack channel after an AI agent configured on Grok Bot was executed. Grok claims to have identified a routing confusion and deployed a permissions fix. This incident raises the question of access control and the separation of work and personal life for the user.
Grok's Fix and Disconnection of Accounts After the Incident
Grok stated that it conducted an investigation, identified the cause of the incident, and deployed a solution the following night to regulate information transfers by agents. Following this event, Shane Mac deleted all his connections and disconnected Google, his calendars, bank accounts, and Stripe. He asserts that more robust controls on agent access are necessary and that the central issue is to build better permission systems so that users maintain control over what they share.
A Routing to "Exec-team" Instead of the Private Agent Group
According to shared findings, the CFO agent did produce the requested report but sent it to a Slack channel titled "Exec-team," which includes XMTP's executive team, instead of the private group where Shane Mac communicates with his AI agents. The confusion was facilitated by channels with the same name. Shane Mac had created several agents and linked Slack to one of them; in practice, these agents operated under the same connections, even when they appeared distinct.
The CFO Agent Tasked with Tracking Monthly Finances
Set up towards the end of August, the CFO agent was supposed to provide monthly balances, monthly and recurring expenses, report any potential fraud, and suggest savings opportunities. Shane Mac had asked it to take on the role of financial advisor, with read-only access to his checking and savings accounts, and to send its messages only to him via Grok Bot. The agent then posted a report in a chat grouping his other agents, named "My Personal Executive Team," used as a small support team. Initially programmed to operate weekly with good results, it derailed during the very first monthly audit.
D-Day on Slack and the Content of the Distributed Report
On Thursday, October 1, the product manager alerted Shane Mac via private message, thinking it was a sharing of XMTP's bank balance. Shane Mac had not anticipated anything like that. As he read through the message, the mention of a barn under construction on Shane Mac's property raised doubts: it was his personal account. The balance of Shane Mac's savings account and the list of his largest expenses for the month showed a marked overspend due to this construction project. When questioned, Grok Bot apologized and indicated that it would delete the message, which had already been erased by Shane Mac.
Useful Uses but a Call for Work/Personal Separation
As the head of XMTP Labs, Shane Mac reports having adopted personal AI agents early on, after trials with OpenClaw, Hermes, and other tools, to automate tasks, local quotes, or bookings. He created a dedicated CFO agent. While he finds these agents useful and believes they will be sought after by users, he feels that current systems need to better explicitly frame permissions, a point also highlighted by Grok. He advocates for a clearer separation between personal and professional uses, citing the use of services like Google at home and at work, and reiterates that the incident illustrates the power of these tools and the necessity for safeguards.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.