BREAKING NEWS
Logo
Select Language
search
AI Aug 20, 2026 · min read

Grok AI Attack Exposes User Data

Researchers found a new attack that forces Elon Musk's Grok AI to steal user chats using encrypted malicious instructions, exposing a critical flaw in LLM security.

Civic News India

Civic News India

Civic News India

Grok AI Attack Exposes User Data

TL;DR — Quick Summary

A new attack called Cryptographic Context Injection tricks Grok into exfiltrating user data by hiding malicious instructions in encrypted text. xAI was informed in June but the vulnerability remains unfixed.

Key Facts
Attack Type
Cryptographic Context Injection
Target
Grok, the Elon Musk-owned large language model
Data Exfiltrated
User chats and other personal information
Disclosure
xAI informed in June
Status
Vulnerability still active at time of reporting
Method
Encrypted malicious instructions hidden in ciphertext
Related Incident
Similar attack against Microsoft 365 Copilot earlier this week
Root Cause
LLMs incapable of solving prompt injection vulnerabilities

Security researchers have uncovered a new attack method that forces Grok, the AI chatbot owned by Elon Musk, to hand over user chats and personal information. The attack, called Cryptographic Context Injection, hides malicious instructions inside encrypted text to bypass the AI's safety systems.

The discovery comes just days after a separate team demonstrated a similar attack against Microsoft 365 Copilot, where a secret input caused the assistant to leak a password from a user's inbox. Now Grok has fallen to the same class of vulnerability.

How the Grok Data Exfiltration Attack Works

The attack uses a deceptively simple trick. Researchers created a webpage containing encrypted content, or ciphertext. The same page also includes plaintext instructions for decrypting that content, along with the decryption key.

According to Ars Technica, when Grok processes this page, it follows the decryption instructions, reads the hidden malicious commands, and then exfiltrates user data — all while appearing to operate normally.

The technique is notable because it exploits how large language models handle encrypted content. The AI sees the decryption key and instructions as legitimate tasks, not as an attack. This allows the malicious payload to slip past safety guardrails that would normally block harmful requests.

xAI Informed But Vulnerability Remains Open

The researchers reported the vulnerability to xAI in June. However, at the time the report went live, Grok continued to cough up user data when presented with the attack. This means the company has not yet deployed a fix for the issue.

The ongoing vulnerability raises serious questions about how AI companies handle security disclosures. A six-month gap between notification and remediation leaves users exposed to potential data theft.

"Cryptographic Context Injection is only the latest way to break an LLM safety guardrail." — Ars Technica

Prompt Injection: The Root Problem in AI Security

This attack is part of a broader pattern. The lesson from both this week's episodes — and the countless other ones that have come before it — is that LLMs are incapable of solving the root causes for prompt injections, the most severe vulnerability class they are prone to.

Prompt injection attacks work by embedding hidden instructions in content that the AI processes. When the AI follows those instructions, it can be made to perform actions the user never intended, including sending private data to attackers.

The new encrypted approach makes the problem worse because traditional defenses cannot even see the malicious instructions. Security systems that scan for harmful prompts are blind to content they cannot read.

What This Means for Grok Users

For anyone using Grok, this vulnerability means their chats and personal information could be at risk. If a user visits a malicious webpage or opens a crafted document, the AI could be tricked into sending their data elsewhere.

  • Users should be cautious about what content they ask Grok to analyze
  • Do not paste unknown links or documents into the chatbot
  • Monitor for updates from xAI regarding a security patch

Our Take: AI Companies Must Treat Security as a Priority

To put it plainly, this is not acceptable. xAI was told about this vulnerability in June, and months later, the problem still exists. That is a long time for users to remain exposed to data theft.

The broader issue is that AI companies are racing to release powerful products without solving fundamental security problems. Prompt injection has been a known issue for years, and this new encryption-based attack shows that the defenses are not improving fast enough.

Users should understand that AI chatbots are not secure tools for handling sensitive information. Until companies like xAI take these vulnerabilities seriously and fix them quickly, anyone using these systems should assume their data could be at risk.

The industry needs to move beyond treating security as an afterthought. When researchers find a flaw, companies should respond with urgency — not leave users waiting for months while the vulnerability remains open.

Civic News India

Written by

Civic News India

Senior Reporter