Researchers Show Grok Can Be Tricked Into Leaking User Data via Encrypted Prompt Injection

Following a similar exploit against Microsoft 365 Copilot, researchers have devised a prompt-injection attack that forces Grok to exfiltrate user chats and personal information. The attack hides malicious instructions using an encryption-based trick, and Grok was still vulnerable at publication time despite xAI being notified in June.

The recurring incidents highlight that LLMs cannot fix the root causes of prompt injection, the vulnerability class they are most prone to. As a result, developers must rely on guardrails to steer models away from harmful actions, much like adding a protective rail at a dangerous bend instead of banking the curve.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleStanford Study: AI Impact Falls Heaviest on Entry-Level Workers
Start typing to search