Grok chat duped into swallowing injected instructions
xAI’s Grok web chat agent can be tricked via “cryptographic context injection” into decrypting encrypted prompt instructions and then executing them, including a proof-of-concept that exfiltrates the victim’s chat history (name, coarse location, subscription tier, and full prompts) by appending them to a URL as parameters.
Aug 20, 2026 ·
The Register














