Security3 min read
Encrypted instructions can fool Grok and Gemini assistants
Researchers call the technique Cryptographic Context Injection: hide instructions in encrypted data, then trick the agent into decrypting them with its own code tool. On Grok, a summarize-this-page flow could steal a user’s name, approximate location, subscription tier, and chat history with no extra click.
