← Radar

Incident case file

Sign in to watch

Grok 'Cryptographic Context Injection' — Chat Data Exfiltration Vulnerability

Incident date 2026-06-02Last updated Aug 26, 2026

0 views

ActiveNot applicable (AI agent security — xAI's Grok web chatchain-agnostic)AI agent prompt injection — encrypted payload bypassing content-classification guardrails (data exfiltration, not fundCluster: GROK-CCI-2026-08

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Ledger

Attacker

Not applicable (responsible disclosure by security researcher Rony Utevsky, Adversa AI). No malicious in-the-wild exploitation has been reported.

Funds moved to

Not applicable — no cryptocurrency or financial assets were involved. The proof-of-concept exfiltrates a user's name, approximate location, subscription tier, and ongoing chat prompts to an attacker-controlled server.

Linked

Not applicable. Relevant context: this echoes an earlier May 2026 case (the Grok/Bankr incident) which SlowMist classified as 'AI agent permission chain abuse,' where a Morse-code-encoded instruction sent to Grok was decoded and posted publicly, and a third-party automation system (Bankr) treated that public output as a valid authorized command, executing an unintended token transfer. The current CCI vulnerability is a distinct, newer attack class targeting the same underlying platform.

Chronology

1 beat
  1. Jun 3, 2026: Adversa AI reports the 'Cryptographic Context Injection' (CCI) vulnerability to xAI. The technique embeds AES-256-GCM ciphertext, key material, and a decryption instruction on a malicious web page; when Grok processes the page, it decrypts the payload inside its own code-execution sandbox (via PBKDF2 + AES-256-GCM), which no content-safety classifier inspects at that stage, since the classifier only sees ciphertext. xAI acknowledges the report but gives no mitigation timeline. Aug 4 and Aug 10, 2026: Adversa AI attempts further coordinated disclosure contact with xAI. Aug 19, 2026: Adversa AI reproduces the attack once on the live Grok 4.5 Fast model at grok.com, confirming the vulnerability remains unpatched more than two months after initial disclosure. Aug 20, 2026: Public disclosure via The Hacker News, The Register, SecurityWeek, and Ars Technica. Ars Technica independently confirms the exfiltration mechanism is still functioning at time of publication. The technique is noted as directly descended from an earlier, related demonstration against Google Gemini (disclosed as 'Cryptographic Payload Injection' on 11 Mar 2026), indicating this class of attack against LLM guardrails is not unique to Grok. As of publication, xAI has issued no public fix, CVE, or user-facing mitigation.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)