logo

Grok chat duped into swallowing injected instructions

ID: 5f7e47ba-5550-5ab7-a12c-6c6bb5ea2043

STIX ID: report--5f7e47ba-5550-5ab7-a12c-6c6bb5ea2043

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2026-08-20

Date Updated: 2026-08-21

...
...

**Executive summary:** Researchers at Adversa AI demonstrated a novel prompt-injection technique called "cryptographic context injection" that embeds encrypted malicious instructions plus key material on web pages so a model with code/runtime access will decrypt and execute them, bypassing static guardrail scanners; a proof-of-concept exfiltrated Grok chat data and the technique was reported to xAI with no public mitigation timeline as of the report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.