Researchers at Adversa discovered that Grok can be tricked into exfiltrating user data through encrypted malicious instructions, a variant of prompt injection attacks. Despite being notified by June, the vulnerability remained unpatched at the time of publication. The attack underscores the persistent difficulty LLMs face in distinguishing user instructions from injected content, reinforcing that guardrails—not architectural fixes—remain the primary defense.
Background
Prompt injection remains one of the most critical vulnerability classes for AI assistants, especially enterprise tools that process emails and web content. Recent attacks on both Microsoft Copilot and xAI's Grok highlight systemic weaknesses in how LLMs handle untrusted input.
- Source
- Ars Technica
- Published
- Aug 20, 2026 at 09:00 PM
- Score
- 8.0 / 10