← Back to feed
AI SecurityEmerging1 sourceAug 22, 2026 · 05:21via CyberPress

Grok Zero-Click Attack Steals Chat History Through Encrypted Prompt Injection

Brief

A newly disclosed prompt-injection technique can reportedly turn a routine “summarize this page” request in xAI’s Grok web chat into a silent data-exfiltration attack, exposing a user’s name, approximate location, subscription tier, and active conversation history.

Security researchers at Adversa AI named the technique Cryptographic Context Injection. The attack abuses Grok’s ability to browse webpages and execute code in an integrated Python sandbox, allowing hidden instructions on an attacker-controlled page to be decrypted and treated as trusted internal context.

According to Adversa AI, the proof of concept was tested against Grok 4. 5 Fast on grok. com and completed without a confirmation dialog or visible warning.

Read more on CyberPress