Researchers found Grok can be tricked into exfiltrating private user data when malicious instructions are encrypted, the latest jailbreak to bypass LLM guardrails.
Ars Technica reports a technique called Cryptographic Context Injection lets attackers smuggle malicious instructions past Grok's safety filters by encrypting them, causing the model to leak user data. It's the newest entry in a growing list of prompt-injection exploits against production chatbots.
The disclosure lands the same week Grok Lite users separately reported the model sending gibberish responses, raising broader reliability questions about xAI's deployment pipeline.
Every major LLM vendor is now shipping products with unresolved prompt-injection risk, and encryption-based bypasses show attackers are iterating faster than guardrail patches. Any company embedding chatbots into workflows handling sensitive data needs to treat this as an active threat, not a theoretical one.
The daily signal, curated. Get it in your inbox.
Subscribe on LinkedIn →