Adversa bypasses Grok's guardrails by shipping encrypted prompt-injection payloads with the key
Adversa AI researcher Rony Utevsky disclosed cryptographic context injection on August 20, 2026: a poisoned web page carries AES-256-GCM ciphertext plus the PBKDF2 key material and an instruction to decrypt, so the static content classifier sees only unreadable bytes and passes it through, then the model decrypts inside its own sandbox and treats the result as trusted tool output. The proof of concept exfiltrated a Grok.com user's name, coarse location, subscription tier and full conversation by appending them to an attacker URL as a fake decryption key, with no warning or confirmation. xAI was notified June 3 via HackerOne and again on August 4 and 10; the technique still worked as of August 19.
Source
↳ Follow the thread