Grok fooled into stealing user chat, location data, and more

Executive Summary

Researchers discovered that prompt injection attacks can embed malicious commands within encrypted text, bypassing AI guardrails. The attack targeted Grok, causing it to exfiltrate user chat logs, location data, and other sensitive information.


Intelligence Metadata - Source Publisher: Malwarebytes Labs - Published Date: 2026-08-25T11:34:18+00:00 - Category: malware

Original Description: Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.

"As we are liberated from our own fear, our presence automatically liberates others."

— Nelson Mandela
Source: Malwarebytes Labs