BTC $75,127.52 +7.95%
ETH $2,362.03 +5.05%
BNB $665.15 +6.34%
XRP $1.30 +17.63%
SOL $90.05 +5.63%
TRX $0.3380 +1.57%
DOGE $0.0833 +11.26%
ADA $0.2084 +13.46%
BCH $248.09 +17.12%
LINK $10.96 +4.75%
HYPE $72.81 +1.29%
AAVE $100.28 +4.16%
SUI $0.7772 +11.11%
XLM $0.1865 +11.09%
ZEC $598.38 +8.06%
BTC $75,127.52 +7.95%
ETH $2,362.03 +5.05%
BNB $665.15 +6.34%
XRP $1.30 +17.63%
SOL $90.05 +5.63%
TRX $0.3380 +1.57%
DOGE $0.0833 +11.26%
ADA $0.2084 +13.46%
BCH $248.09 +17.12%
LINK $10.96 +4.75%
HYPE $72.81 +1.29%
AAVE $100.28 +4.16%
SUI $0.7772 +11.11%
XLM $0.1865 +11.09%
ZEC $598.38 +8.06%

Grok has a "cryptographic context injection" vulnerability, putting user chat data at risk of leakage

2026-08-21 09:42:43

According to Cryptopolitan, cybersecurity company Adversa AI disclosed that xAI's AI assistant Grok has a security vulnerability known as "cryptographic context injection." Attackers can hide cryptographic commands within ordinary web pages, and when users request Grok to summarize the page, Grok automatically decrypts and executes the hidden commands, sending the user's name, geographical location, subscription level, and complete chat history to the attacker's server.

The vulnerability was reported to xAI through the HackerOne platform on June 3, 2026. Researcher Rony Utevsky followed up on August 4 and 10, but as of August 19, the vulnerability had still not been fixed on Grok.com, and xAI had not provided a patch timeline.

app_icon
ChainCatcher Building the Web3 world with innovations.