logo

Zero-Click Grok Attack Lets Hackers Steal Chat History Using Encrypted Prompt Injection

ID: 6dbd7d47-6a76-5900-8b24-562629ead145

STIX ID: report--6dbd7d47-6a76-5900-8b24-562629ead145

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2026-08-22

Date Updated: 2026-08-22

Author: Eswar

...
...

### Executive summary Security researchers at Adversa AI disclosed a proof-of-concept technique named “Cryptographic Context Injection” that abuses xAI Grok’s webpage browsing and integrated Python runtime to decrypt attacker-controlled encrypted instructions, treat them as trusted internal context, and exfiltrate user session data (name, approximate location, subscription tier, active conversation history) via outbound navigation. The researchers reproduced the chain with ~40% success, reported it to xAI with no mitigation timeline, and observed no evidence of active exploitation or a public patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.