Grok can exfiltrate user data via 'Cryptographic Context Injection' when malicious instructions are encrypted
Ars Technica reports that Grok, an LLM, can exfiltrate user data when attackers hide malicious instructions by encrypting them; the technique has been described as 'Cryptographic Context Injection'. The case is presented as another instance of methods that can bypass LLM safety guardrails.