Breaking
August 20, 2026

Encrypted web page payload turns Grok into a chat history leak Randa Moses | usagoldmines.com

Grok is still handing users’ private chat data to hackers, according to a report from Adversa AI published on Thursday.

Hackers get ahold of this data through injecting commands in encrypted text that sits in regular-looking web pages. The cybersecurity firm alerted xAI more than two months ago; however, there’s no fix available yet.

Ciphertext flows through Grok’s filter

Adversa researcher Rony Utevsky named the attack “cryptographic context injection.” It passes the chatbot’s own safety filter easily.

Most LLMs filter incoming and outgoing text for suspicious commands. However, this attack hides malicious text from Grok’s filter.

The malicious instruction is encrypted, leaving only the ciphertext, the key, and a note on how to decrypt it on the page.

The filter reads text but never runs it, so ciphertext passes through. Grok then decrypts it inside its code sandbox. It treats the plaintext that pops out as a trusted tool output.

“The runtime execution launders attacker-controlled data into trusted instructions the agent will act upon,” Adversa wrote in its disclosure.

When a user asks Grok to summarize or analyze a webpage, the assistant fetches it, decrypts the hidden payload, and follows it.

The decrypted instructions tell Grok to make something that looks like a decryption key. It’s derived from the user’s name, coarse location, subscription tier, and the complete set of prompts from that conversation.

It is then attached to a URL that directs to the attacker’s server. Once Grok opens the URL, the data lands in the attacker’s logs.

xAI has been sitting on the report since June 3

xAI has been aware of this attack since June 3, 2026, when Utevsky reported the bug directly and through the company’s HackerOne program for bug bounties.

xAI has noted the report but has not given a timeline for a patch. Utevsky says he raised it again on August 4 and August 10. As of August 19, the exploit was still working on Grok.com.

Adversa is only publishing the attack mechanism, and the recommended fix is in the agent’s harness.

Days ago, Google’s Gemini 3.7 Flash model generated material normally blocked by its filters. This includes instructions for building an incendiary weapon and a copy of the model’s own system prompt.

That version is a direct jailbreak. Utevsky said this is because Gemini’s Python environment can’t reach outside websites. Google considers jailbreaks to be outside of the scope of its disclosure program.

Gemini’s success rate dropped sharply by August. Adversa could not point to a filter update, a model change, or both as the cause.

In May, Cryptopolitan reported that a user on X wrote a message in Morse code that bypassed the bot’s safeguards and got Grok to tell the linked agent Bankrbot to send around $200,000 in DRB tokens on Base.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It’s free.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.