New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
16:36 · August 20, 2026 · Hacker News AI Section

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the
Summary
Adversa AI has identified a vulnerability in xAI's Grok chatbot that relies on a technique called Cryptographic Context Injection. The method works by embedding instructions in a web page so that, when a user requests a summary, the model transmits session data to an external server controlled by the attacker.
The leaked material includes the user's name, approximate location, subscription tier, and the prompts from the active conversation. No further user action is required beyond the initial summarization request, and the page itself can appear as ordinary content to the person viewing it.
The disclosure underscores how large language models that incorporate both external documents and persistent session context can inadvertently expose metadata when processing untrusted input. The technique targets the way Grok handles page content alongside conversation state rather than relying on conventional prompt injection alone.
Why it matters
This article highlights a critical data exfiltration vulnerability in LLMs via context injection, which is highly relevant for security professionals defending AI systems. Understanding this attack vector is essential for Dutch enterprises to ensure GDPR compliance and protect user privacy when deploying AI chatbots.







