What We Know
Security researchers with Adversa AI describe a prompt-injection technique called Cryptographic Context Injection that targets xAI’s Grok web chat agent. Source 0, Source 12Backed by 2 sourcesadversa.aiThe Register The technique places attacker-controlled instructions in a webpage and encrypts them, allowing the commands to evade plaintext-oriented guardrails while still being processed by Grok in a trusted context. Source 0, Source 1, Source 52Backed by 2 sourcesadversa.aiThe Register
The reports frame the issue as a broader risk for AI assistants that can browse webpages or access code tools and private information, because content treated as data may contain instructions that redirect the assistant’s behavior. Source 1, Source 41Backed by 1 sourcesmalwarebytes.com
Source Comparison
Aligned reportingCorroborates
- adversa.ai↗Adversa AI identifies Cryptographic Context Injection as a way to bypass guardrails and have attacker commands processed in a trusted context.
- The Register↗The report attributes Grok's vulnerability to a novel prompt-injection technique developed by Adversa AI and describes attackers creating a poisoned webpage.
- malwarebytes.com↗The report connects the attack to theft of chat and location data and warns that assistants with browser, code-tool, and private-data access require extra caution.
Adds context
- Ars Technica↗The headline highlights the reported outcome—Grok exfiltrating user data when malicious instructions are encrypted—but provides no further detail in the supplied material.
- Security Affairs↗The headline specifically identifies a zero-click chat-history theft demonstration involving Adversa AI and Cryptographic Context Injection.
- suriq.io↗The article gives narrower support for the mechanism and impact: encrypted webpage instructions reportedly made Grok leak chat history and session data, while noting that plaintext filters may miss the instructions.