Researchers have demonstrated a new prompt-injection attack against Grok that uses encrypted malicious instructions to force the AI assistant to exfiltrate user chats and other personal data. The technique mirrors a similar attack against Microsoft 365 Copilot disclosed earlier this week.
Grok remained vulnerable at the time of writing despite xAI having been notified in June. The findings underscore that large language models cannot address the root causes of prompt injections, leaving developers to rely on guardrails to block harmful actions.
Comments