Y Combinator's Paxel AI Tool Claims Local Analysis But Security Audit Reveals Data Uploads to External Servers

According to Beating, Y Combinator released Paxel, a free AI coding analysis tool claiming code "never leaves your machine." Hours after launch, security researchers reverse-engineered the tool and exposed the claim as false. Analysis revealed Paxel frequently transmits sensitive data: file contents, code modifications, prompt inputs, local file paths, Bash commands, and Git credentials are sent to YC servers. Sentry error monitoring also runs by default, continuously transmitting code line counts and Git commit history externally. The discovery contradicts Paxel's local-run assurance.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments