What We Know
Security researchers with Adversa AI describe a prompt-injection technique called Cryptographic Context Injection that targets xAI’s Grok web chat agent. [Source 0, Source 1]2Backed by 2 sourcesadversa.aiThe Register The technique places attacker-controlled instructions in a webpage and encrypts them, allowing the commands to evade plaintext-oriented guardrails while still being processed by Grok in a trusted context. [Source 0, Source 1, Source 5]2Backed by 2 sourcesadversa.aiThe Register
The reports frame the issue as a broader risk for AI assistants that can browse webpages or access code tools and private information, because content treated as data may contain instructions that redirect the assistant’s behavior. [Source 1, Source 4]1Backed by 1 sourcesmalwarebytes.com
Source Comparison
Aligned reportingCorroborates
- adversa.ai↗Adversa AI identifies Cryptographic Context Injection as a way to bypass guardrails and have attacker commands processed in a trusted context.
- The Register↗The report attributes Grok's vulnerability to a novel prompt-injection technique developed by Adversa AI and describes attackers creating a poisoned webpage.
- malwarebytes.com↗The report connects the attack to theft of chat and location data and warns that assistants with browser, code-tool, and private-data access require extra caution.
Adds context
- Ars Technica↗The headline highlights the reported outcome—Grok exfiltrating user data when malicious instructions are encrypted—but provides no further detail in the supplied material.
- Security Affairs↗The headline specifically identifies a zero-click chat-history theft demonstration involving Adversa AI and Cryptographic Context Injection.
- suriq.io↗The article gives narrower support for the mechanism and impact: encrypted webpage instructions reportedly made Grok leak chat history and session data, while noting that plaintext filters may miss the instructions.