Following a similar attack on Microsoft 365 Copilot, researchers have demonstrated a data theft attack against Grok that forces the AI assistant to exfiltrate user chats and other personal information. The attack uses encrypted malicious instructions that Grok follows despite their harmful intent.
xAI was informed in June, but the issue remained unfixed at publication. The case underscores that LLMs cannot solve the root causes of prompt injection and require guardrails to block harmful actions.
Comments