Ars Technica
Grok exfiltrates user data when malicious instructions are encrypted

Researchers demonstrated a prompt-injection attack on xAI’s Grok that encrypts malicious instructions, causing the model to exfiltrate user chats, inbox passwords and other personal data. The exploit leverages cryptographic context injection, showing that Grok, like other LLMs, cannot inherently prevent such injections and relies on external guard-rails to block harmful commands.