Skip to content

BuildIndependently confirmed2 publishers2 min readPublished

Shane Mac's read-only Grok Bot agent posted his bank audit in XMTP's exec Slack

Shane Mac's Grok Bot agent posted his personal bank balances and spending into his company's executive Slack channel. The agent's bank access was read-only, a limit on what it could do to the accounts that left open where it could send what it read.

The Engineer · Build desk

How we use AISend a correction

Photograph accompanying Shane Mac's read-only Grok Bot agent posted his bank audit in XMTP's exec Slack
Photo: gadgetreview.com

What happened

  • Mac said his agents appeared separate but all ran on the same underlying connections, so the Slack link he gave one of them was open to the finance agent.
  • xAI's security documentation, last updated September 16, says all of a user's Bots share one cloud computer and should not be treated as a security boundary.
  • Mac said the Grok team told him it had shipped a change requiring users to explicitly grant agents permission before they move information into other channels.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint Making an agent read-only on a data source does not limit disclosure; once that agent also holds a messaging connection, only a separate egress control decides where its output lands.
  • decision Under xAI's documented model, anyone keeping finance and work Bots on one account has to treat them as one principal with one set of credentials, or keep sensitive connections off that account.
  • exposure Agents that resolve destinations by display name make every pair of similarly named channels a misrouting risk, and the person whose data the agent reads bears the cost.
  • contradiction The fix is known only through Mac's retelling of what the Grok team said, against documentation that predates it, so operators cannot yet check whether the grant is enforced per channel.

Mac's read-only grant was a limit on the bank side. As runtimewire put it, the grant constrained what the agent could do to his accounts and did not stop what it read from being sent somewhere else [13]. The rule for the other side was an instruction: send reports only to Mac, through Grok Bot [12]. An instruction like that holds only as long as the model picks the right destination on every run.

The weekly reports ran without incident. The error surfaced on the first monthly audit [17]. The post went out under Mac's identity. "As me," he tweeted [2]. XMTP's head of product spotted it and at first took the figures for company financials [7]. The Grok team traced the misdirection to the lookalike channel names, Mac said [15]. After Mac confronted it, the bot replied that it was "checking Exec Team now and deleting it if it's still up" [5]. That string matches neither channel name exactly [21]. Mac deleted the message before the agent got there [6].

xAI's security documentation was last updated 15 days before the post [22]. The shared-machine design was public before Mac hit it, and credit to xAI for stating the limit in plain words. It means a role label is only a label. A name such as "CFO" describes a task and does not fence off the accounts and destinations available across agents, runtimewire noted [10].

The reported change adds a grant on the destination side, where the leak happened. Mac's account does not say how it was built [11]. I'd expect it to hold only if the grant is checked when the tool call executes and is keyed to a specific channel, not to a name the model interprets. A permission the model is asked to remember is the same kind of control as the instruction Mac had already given [12].

The whole sequence rests on Mac's account. Futurism said it could not independently verify his claims, and noted that he is building a tool that connects AI agents and lets users set rules for them [18]. His original tweet was viewed almost 800,000 times [19]. Mac said the post was "not fake at all" [20].

His own remedy was cruder than the vendor's. He disconnected Google, his calendars, banking and Stripe, among other services [9]. "There needs to be a much clearer line between personal and work life," he wrote in Business Insider [8].

What to watch

  • A revision of xAI's security documentation, last dated September 16, that describes the channel-permission grant and whether it is enforced at the tool call per destination.
  • Any change to the shared cloud computer model that would let separate Grok Bots under one user hold separate credentials.
  • Confirmation of the fix from xAI itself, since Futurism could not independently verify Mac's account.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives65
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Shane Mac's personal finance agent sent a bank audit to XMTP's executive Slack channel; the post went up on October 1 and included his personal checking and savings balances and major expenses.

    ReportedSupportedSource: Mac's account in Business Insider, as reported by runtimewire2 sources— create a free account to open themView cited source
  2. [2]

    "Last Thursday, an AI agent posted my personal bank balances into our company Slack. As me."

    ReportedSupportedSource: Shane Mac, tweet quoted by Futurism2 sources— create a free account to open themView cited source
  3. [3]

    Mac said he had connected Slack to one of his other agents, but all the agents used the same underlying connections even though they appeared to be separate.

    ReportedSupportedSource: Mac, via runtimewire2 sources— create a free account to open themView cited source

Sources

2 independent publishers whose own reporting we read for this story.

  1. futurism.com

    1 article · October 7, 2026

    Man Says He Was Mortified When His AI Agent Posted His Bank Balances and Exactly What He's Spending His Money on in a Slack Work Channel
  2. runtimewire.com

    1 article · October 9, 2026

    XMTP Labs CEO says Grok Bot added channel permissions after his bank audit hit Slack

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories