
Our research team has been tracking how public AI features get abused in the wild, and grok.com turned up a textbook case. Run a simple site:grok.com query in Google and you do not get pages about Grok the assistant. You get a wall of casino and gambling spam: slot promos, fish-shooting betting games, sportsbook funnels, in English and Vietnamese, each one living on a genuine grok.com URL. Spammers have quietly turned Grok’s public “share chat” feature into a free, high-authority host for search spam.
What our experts found
The pattern is consistent. Someone opens Grok, prompts it to write keyword-optimised marketing copy for a gambling brand, then publishes the conversation as a public page under grok.com/share/…. Google crawls and indexes it like any other page on the domain. Because grok.com is a brand-new, extremely high-authority domain, those share pages rank fast and rank well — for queries that have nothing to do with Grok.
We saw the same playbook repeated across markets. English-language slot spam like “Golden Genie: Your Fun Casino Adventure.” Aggressive Vietnamese gambling targeting — “Bắn Cá Tài Lộc” (fish-shooting betting), “Nổ Hũ” (jackpot slots), virtual sports betting. Each shared chat is padded with on-page keywords and, crucially, a block of outbound links to the operator’s real money sites: cf789, mcw casino, Casino Online, and others. Some of the indexed results even show “The shared chat you are trying to access has been deleted or is no longer available” — the spam page was created, indexed by Google, then deleted, yet the URL still sits in the results. The abuse leaves residue even after cleanup.
| Shared-chat title | Target market | What it funnels to |
|---|---|---|
| “Golden Genie: Your Fun Casino Adventure!” | English | Online slots; outbound links to “mcw casino” repeated |
| “Bắn Cá Tài Lộc — Trải Nghiệm Giải Trí Cá Cược” | Vietnamese | Fish-shooting betting; links to cf789, Casino Online, Nổ Hũ |
| “Quần Vợt Ảo Giải Trí Cá Cược Hấp Dẫn” | Vietnamese | Virtual tennis / sports betting funnels |
How the abuse works: parasite SEO on an AI platform
This is a well-worn technique called parasite SEO, and AI chat platforms just became its newest host. The recipe is old; only the victim is new:
- Borrow the authority. Ranking a fresh casino domain in Google is hard and slow. Publishing on a domain Google already trusts is instant. grok.com carries enormous authority, so its subpages inherit ranking power the spammer never earned.
- Let the AI write the spam. The same model that helps you draft an email will happily generate keyword-stuffed gambling copy on request. The attacker does not even have to write the content — Grok does.
- Make it public and indexable. The share feature turns a private chat into a crawlable page with no
noindex, and the outbound links are followed rather than markednofollow/ugc. That passes both traffic and link equity to the casino sites. - Scale it. Creating share pages is free and unlimited, so the same operator spins up page after page across languages and brands.
Why this matters
It is easy to dismiss this as harmless SEO junk. It is not. Search users are handed gambling and scam funnels wrapped in the credibility of a well-known AI brand — a Google result on grok.com reads as trustworthy. For xAI, it is a reputation and search-hygiene problem: Google has historically penalised authority domains that let their UGC sections fill with spam, and a polluted /share namespace invites exactly that scrutiny.
The bigger point for anyone defending an AI product: a public share feature is an attack surface, not a convenience. This is the same class of problem we keep flagging as AI systems get woven into everything — and it belongs in your threat model for agentic and generative AI. Grok is simply the most visible example today; every platform with a public “share this chat” button faces the identical risk, just as every platform with an API faces abuse. It sits alongside the trend we tracked in the state of AI cyber models and the weaponisation of AI agents in the recent PaperCut mass-exploitation campaign: the tooling is neutral, the abuse is not.
What platforms and defenders should do
For platform teams running a public share feature, the fixes are known and cheap:
- Add
noindexto user-generated share pages, or at least gate indexing behind review — a shared chat almost never needs to rank in Google. - Mark every outbound link in shared content
rel="nofollow ugc"so the domain’s authority stops laundering link equity to third parties. - Rate-limit and content-filter share creation: detect gambling, adult and pharma keyword clusters and block or quarantine them before they are ever published.
- Purge deleted-chat URLs from the index promptly (410 responses, sitemap hygiene) so takedowns actually take effect.
For brand and security teams on the other side of the screen: monitor site: queries on the big AI domains for your brand name and your industry’s spam clusters, and report parasite pages to Google. If you run affiliate or gambling-adjacent verticals, watch for competitors laundering links or negative-SEO campaigns riding these platforms.
Bottom line
Grok did not get hacked. A legitimate feature was pointed at search engines and turned into a spam cannon, powered by the platform’s own domain authority and its own text generation. It is a small, clear preview of a larger shift: as AI platforms accumulate trust and traffic, they become high-value hosts for the oldest tricks in the book. Public share features need to be treated as what they are — a publishing surface — and secured accordingly, before the next site: query on your favourite AI brand comes back full of casinos.