logo

Encrypted Prompts Defeat Grok and Gemini Guardrails; Chat Histories Stolen

ID: 49138db2-52ae-5679-85f9-c8a3725e9111

STIX ID: report--49138db2-52ae-5679-85f9-c8a3725e9111

Feed Name: The Cyber Express

Threat Score
65/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Mihir Bagwe

...
...

Adversa AI disclosed "Cryptographic Context Injection," a technique that embeds AES-256-GCM ciphertext in web content so agentic LLMs decrypt and execute hidden instructions inside their code-execution sandboxes, bypassing text-based guardrails; researchers showed zero-click exfiltration of Grok chat histories and dangerous output from Gemini, highlighted limited vendor engagement and disclosure gaps, and warned that content-based guardrails cannot inspect payloads that only exist in plaintext after model execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.