ADVERSA AI has introduced a new attack method called Cryptographic Context Injection, which allows hackers to steal chat histories from AI systems like xAI's Grok and Google's Gemini without any user interaction. This technique involves sending encrypted commands that the AI decrypts during execution, bypassing the systems' safety measures. In a demonstration, a user request to summarize a webpage resulted in Grok accessing private user data and leaking it through URLs without any click or notification.
The method exploits vulnerabilities in the AI's frameworks rather than the models themselves, indicating a significant security flaw. Adversa recommends improved handling of untrusted content within AI contexts to prevent such exploitations.