Researchers Encrypted a Prompt Injection. Grok Decrypted It and Leaked the User's Chat.
Grok refused the plain-text instructions. Encrypted with AES-256, the same instructions cleared the filter, ran in Grok's own sandbox, and sent the user's chat to a stranger.