Grok Chat Duped Into Swallowing Injected Instructions
Researchers said the attack worked 20 times since June and could expose session data by hiding malicious instructions inside encrypted webpage content.
5 Articles
5 Articles
Researchers hid an attack inside AES encryption. The AI model cracked it open willingly.
Security filters are designed to catch malicious instructions before an AI model can act on them. Researchers at AI security firm Adversa found a way around that assumption by giving the model an encrypted payload and letting it create the malicious instructions itself. In an attack demonstrated against xAI’s Grok, the model rejected data-exfiltration instructions when they appeared on a webpage in plain text. But when researchers encrypted the …
Grok exfiltrates user data when malicious instructions are encrypted
Earlier this week, researchers outlined an attack that used a secret input provided by Microsoft 365 Copilot for enterprise to cause the AI assistant to exfiltrate a password present in the user’s inbox. Now, a separate team has devised a similar attack against Grok. The new data theft hack employs a deceptively simple trick to force the Elon Musk-owned LLM to steal user chats and other personal information. At the time this post went live, the …
Grok chat duped into swallowing injected instructions
xAI's Grok web chat agent is currently vulnerable to a novel form of prompt injection, according to security researchers with Adversa AI. The technique allows an attacker to create a web page poisoned with malicious instructions that induce an AI model summarizing the page to carry out harmful actions. That describes a well-known attack known as indirect prompt injection. Frontier AI models have become better at dealing with such attempts throug…
Grok leaks user chats via encrypted webpage trick, 11 weeks after xAI warned
Grok is still handing users’ private chat data to hackers, according to a report from Adversa AI published on Thursday. Hackers get ahold of this data through injecting commands in encrypted text that sits in regular-looking web pages. The cybersecurity firm alerted xAI more than two months ago; however, there’s no fix available yet. Ciphertext flows through Grok’s filter Adversa researcher Rony Utevsky named the attack “cryptographic context in…
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








