Cryptographic Context Injection Attack Exploits Grok Chatbot to Exfiltrate User Data
A cryptographic context injection attack exploits xAI's Grok chatbot to exfiltrate user data by embedding encrypted payloads that bypass content classifiers, while a similar technique targeting Google's Gemini was also demonstrated. The attack highlights vulnerabilities in AI agent security frameworks, with no patch or mitigation reported from xAI as of August 20, 2026.
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page.
The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the
*** END OF TRANSMISSION ***