LATEST NEWS
SELECTED FOR YOU

Grok leaks user chats via encrypted webpage trick, 11 weeks after xAI warned

ByRanda MosesRanda Moses 2 mins read
Grok leaks user chats via encrypted webpage trick, 11 weeks after xAI warned.
  • Adversa AI showed that Grok will leak a user’s name, location, subscription tier, and entire chat history.
  • It will give this information to an attacker who hides encrypted commands on a web page that the user asks Grok to summarize.
  • The flaw was disclosed to xAI on June 3, 2026, followed up on August 4 and August 10, and still worked on Grok.com as of August 19 with no mitigation timeline.

Grok is still handing users’ private chat data to hackers, according to a report from Adversa AI published on Thursday.

Hackers get ahold of this data through injecting commands in encrypted text that sits in regular-looking web pages. The cybersecurity firm alerted xAI more than two months ago; however, there’s no fix available yet.

Ciphertext flows through Grok’s filter

Adversa researcher Rony Utevsky named the attack “cryptographic context injection.” It passes the chatbot’s own safety filter easily.

Most LLMs filter incoming and outgoing text for suspicious commands. However, this attack hides malicious text from Grok’s filter.

The malicious instruction is encrypted, leaving only the ciphertext, the key, and a note on how to decrypt it on the page.

The filter reads text but never runs it, so ciphertext passes through. Grok then decrypts it inside its code sandbox. It treats the plaintext that pops out as a trusted tool output.

“The runtime execution launders attacker-controlled data into trusted instructions the agent will act upon,” Adversa wrote in its disclosure.

When a user asks Grok to summarize or analyze a webpage, the assistant fetches it, decrypts the hidden payload, and follows it.

The decrypted instructions tell Grok to make something that looks like a decryption key. It’s derived from the user’s name, coarse location, subscription tier, and the complete set of prompts from that conversation.

It is then attached to a URL that directs to the attacker’s server. Once Grok opens the URL, the data lands in the attacker’s logs.

xAI has been sitting on the report since June 3

xAI has been aware of this attack since June 3, 2026, when Utevsky reported the bug directly and through the company’s HackerOne program for bug bounties.

xAI has noted the report but has not given a timeline for a patch. Utevsky says he raised it again on August 4 and August 10. As of August 19, the exploit was still working on Grok.com.

Adversa is only publishing the attack mechanism, and the recommended fix is in the agent’s harness.

Days ago, Google’s Gemini 3.7 Flash model generated material normally blocked by its filters. This includes instructions for building an incendiary weapon and a copy of the model’s own system prompt.

That version is a direct jailbreak. Utevsky said this is because Gemini’s Python environment can’t reach outside websites. Google considers jailbreaks to be outside of the scope of its disclosure program.

Gemini’s success rate dropped sharply by August. Adversa could not point to a filter update, a model change, or both as the cause.

In May, Cryptopolitan reported that a user on X wrote a message in Morse code that bypassed the bot’s safeguards and got Grok to tell the linked agent Bankrbot to send around $200,000 in DRB tokens on Base.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Randa Moses

Randa Moses

Randa Moses is an editor and reporter at Cryptopolitan covering tech, AI, robotics, crypto, scams, and hacks. She has worked in the crypto space since 2017. She held roles at Forward Protocol, AmaZix, and Cryptosomniac. Randa holds a degree in Electrical and Electronics Engineering from the University of Bradford.

MORE … NEWS