Encrypted instructions on a web page make Grok hand over a user's chat history
Adversa AI reported the attack to xAI on 3 June and reproduced it again on 19 August; there is still no patch, no CVE and no workaround a user can apply.
- Adversa AI disclosed "cryptographic context injection": a web page carries an encrypted block of instructions plus the key to decrypt it, and Grok runs the decryption itself in its own sandbox.
- Content classifiers cannot read ciphertext, so the malicious instructions pass the guardrail unexamined and are only assembled after the check has already been cleared.
- In the demonstration Grok appended the user's name, coarse location, subscription tier and conversation history to a URL and fetched it, sending the data to a server the researchers controlled.
- Adversa reported it to xAI and HackerOne on 3 June and followed up on 4 and 10 August; the attack still worked on 19 August against Grok 4.5 Fast at grok.com.