Encrypted instructions can fool Grok and Gemini assistants
Researchers call the technique Cryptographic Context Injection: hide instructions in encrypted data, then trick the agent into decrypting them with its own code tool. On Grok, a summarize-this-page flow could steal a user’s name, approximate location, subscription tier, and chat history with no extra click.

On August 25, 2026 Malwarebytes reported that encrypted instructions can fool AI assistants such as Grok and Gemini.
What we know
- Cryptographic Context Injection hides instructions in encrypted data, then tricks the agent into decrypting them with its code tool.
- On Grok, a summarize-this-page action could steal a name, approximate location, subscription tier, and chat history with no extra click.
- On Gemini, the technique could bypass refusals.
- Researchers withheld full details, saying xAI had not acted after a June 2026 report.
- Gemini has received partial fixes.
Takeaways
- The attack abuses the assistant’s own decrypt-and-run tooling.
- Grok’s page-summary path leaked account and chat data without a second click.
- Researchers say xAI had not acted months after the June report; Gemini is only partly patched.
Source: Malwarebytes


