Grok is still handing usersβ private chat data to hackers, according to a report from Adversa AI published on Thursday.
Hackers get ahold of this data through injecting commands in encrypted text that sits in regular-looking web pages. The cybersecurity firm alerted xAI more than two months ago; however, thereβs no fix available yet.
Ciphertext flows through Grokβs filter
Adversa researcher Rony Utevsky named the attack βcryptographic context injection.β It passes the chatbotβs own safety filter easily.
Most LLMs filter incoming and outgoing text for suspicious commands. However, this attack hides malicious text from Grokβs filter.
The malicious instruction is encrypted, leaving only the ciphertext, the key, and a note on how to decrypt it on the page.
The filter reads text but never runs it, so ciphertext passes through. Grok then decrypts it inside its code sandbox. It treats the plaintext that pops out as a trusted tool output.
βThe runtime execution launders attacker-controlled data into trusted instructions the agent will act upon,β Adversa wrote in its disclosure.
When a user asks Grok to summarize or analyze a webpage, the assistant fetches it, decrypts the hidden payload, and follows it.
The decrypted instructions tell Grok to make something that looks like a decryption key. Itβs derived from the userβs name, coarse location, subscription tier, and the complete set of prompts from that conversation.
It is then attached to a URL that directs to the attackerβs server. Once Grok opens the URL, the data lands in the attackerβs logs.
xAI has been sitting on the report since June 3
xAI has been aware of this attack since June 3, 2026, when Utevsky reported the bug directly and through the companyβs HackerOne program for bug bounties.
xAI has noted the report but has not given a timeline for a patch. Utevsky says he raised it again on August 4 and August 10. As of August 19, the exploit was still working on Grok.com.
Adversa is only publishing the attack mechanism, and the recommended fix is in the agentβs harness.
Days ago, Googleβs Gemini 3.7 Flash model generated material normally blocked by its filters. This includes instructions for building an incendiary weapon and a copy of the modelβs own system prompt.
That version is a direct jailbreak. Utevsky said this is because Geminiβs Python environment canβt reach outside websites. Google considers jailbreaks to be outside of the scope of its disclosure program.
Geminiβs success rate dropped sharply by August. Adversa could not point to a filter update, a model change, or both as the cause.
In May, Cryptopolitan reported that a user on X wrote a message in Morse code that bypassed the botβs safeguards and got Grok to tell the linked agent Bankrbot to send around $200,000 in DRB tokens on Base.
If you're reading this, youβre already ahead. Stay there with our newsletter.


















English (US)