Prompt Injections Can Now Be Encrypted: Attacks Planted in Encrypted Blocks Replayed into Later Sessions

lbeurerkellner · x · 2026-08-14

The author notes that prompt injections can now be encrypted: worse, an attack planted in an encrypted block and replayed into a later session is adopted by the model as its own prior reasoning, with nothing appearing in the visible conversation.

Related event: European Researchers Crack Encrypted CoT of Top LLMs(13 posts)→

Original post →

More from Safety

Safety channel →