Researchers Find Way to Trick Grok Chatbot Into Leaking Private Chat Data
Cybersecurity firm Adversa AI has revealed a new attack method, dubbed 'Cryptographic Context Injection,' that targets xAI's Grok chatbot. According to the researchers, the attack can be triggered simply by having a user ask Grok to summarise an ordinary-looking web page. Hidden instructions embedded in that page can cause Grok to quietly send the user's name, approximate location, subscription tier, and even the contents of their ongoing conversation to a server controlled by the attacker.
This type of attack, known broadly as prompt injection, exploits the way AI chatbots process and act on text found within web content, rather than treating it purely as information to summarise. Because the malicious instructions are disguised within the page itself, users have no visible warning that anything unusual is happening — the chatbot appears to be doing exactly what was asked.
For Australian small businesses increasingly relying on AI chatbots for research, customer service, or internal tasks, this disclosure is a reminder that AI tools can introduce new and unexpected data exposure risks, even when used for seemingly harmless tasks like reading a webpage.