Elon Musk asked Grok to order Star Wars Lego sets for him and decided to share the results with his more than 240 million followers on X. But the billionaire's demonstration of AI-powered shopping came with an unintended disclosure: the screenshot he posted revealed two addresses in Texas, order information and the last four digits of one of his credit cards, or at least a card used for the purchase.
"I asked Grok to find the Star Wars Lego sets that are the most fun for little kids to play with and order them. It's that simple," Musk wrote in a post over the weekend, attaching a screenshot from Lego's website showing what appeared to be a successfully completed purchase.
The screenshot included a shipping address in Austin, Texas, a separate billing address, an American Express card ending in 7005, an email address and an order number. The total came to $241.34 for five items.
Social media users quickly spotted the exposed information. International Cyber Digest, an X account focused on cybersecurity, shared the image with a sarcastic caption: "Cybersecurity level: Broadcasting my home address and order details to 242 million followers."
Musk responded to the criticism, seeking to clarify that the address was not his home. "That's the address where I receive my mail, by the way, not where I live," he wrote in response to the post.
Even if the address is not Musk's residence, publicly linking a physical location to one of the world's most prominent billionaires carries potential security risks. The location could be flooded with unwanted letters and packages, while people handling deliveries there could face risks involving suspicious or potentially dangerous shipments.
There is currently no indication of a specific threat, but the exposure creates an unnecessary vulnerability, particularly for someone as famous and controversial as Musk.
Want to buy something? Just photograph your credit card
The embarrassing disclosure comes as Musk is actively promoting the shopping capabilities of Grok, the AI chatbot developed by his company xAI. In another post over the weekend, he suggested an especially simple way for users to make purchases through the system.
"To buy things, you can simply take a picture of your credit card, upload it to the chat, and Grok will search the internet for the best deal on the product you want and order it," Musk wrote.
The suggestion raises significant privacy and cybersecurity questions, particularly because xAI itself warns users against sharing sensitive personal information with Grok.
Under xAI's privacy policy, the company may retain content uploaded by users, including images, and use it to improve its services and train AI models. Deleted conversations are generally supposed to be removed from its systems within 30 days, subject to certain exceptions.
Grok Bot, the AI agent Musk used to demonstrate the purchase, is designed to carry out tasks using digital tools, including browsing the internet and interacting with websites. However, the screenshot Musk published does not establish whether the order was completed entirely autonomously or whether he had to approve the payment himself.
AI agents bring new convenience and new risks
Grok's ability to make purchases is part of a broader trend across the artificial intelligence industry. Companies including OpenAI, Google and Anthropic are developing AI agents capable of taking actions on behalf of users rather than simply answering questions or generating content.
These agents can browse the web, interact with online services, order products and perform tasks that previously required direct human involvement.
But as AI systems gain greater access to personal accounts, payment methods and sensitive information, the potential consequences of mistakes, security breaches and misuse also increase.
The risks become particularly acute when users give an AI system access to financial credentials, especially if they do not fully understand how that information is stored, processed or shared.
For now, Musk continues to promote Grok as a convenient way to shop online, even encouraging users to upload photographs of their credit cards.
His own shopping demonstration, however, illustrates an uncomfortable contradiction: a tool designed to make online purchases easier can also expose information its users never intended to share.
The larger question is what happens to sensitive financial information once it enters an AI system, who can access it and who is responsible if something goes wrong.



