A bare 'hi' reportedly triggered tool calls on another user's workspace, exposing Grok session isolation failure
Desperate-Ad117 · reddit · 2026-09-13
A Reddit user reports that during June, Grok coding sessions could apparently be hijacked by sending a stateless 'hi' — with an empty tools list, the model still returned finishreason: toolcalls and executed readfile/grep against another user's workspace.
The author argues this wasn't a chatbot hallucination but a serving-layer session isolation failure: one tenant's context was reachable from another, meaning a single prompt could pull someone else's files, tools, and private session. Dismissing it as a hallucination and deprecating the model, the author notes, doesn't prove the mix-up can't happen on whatever replaced it.
Related event: Grok Build Environment Suspected of Tenant Isolation Flaw(2 posts)→
More from Safety
- OpenAI Researcher Warns AI-Driven Military Power Will Concentrate in Frontier Labs — jachiam0 · 2026-09-13
- Suchenzang: near-zero odds labs agree on a credible third-party safety evaluator — suchenzang · 2026-09-13
- Naval: strict liability could settle the AI safety debate—rogue agents and weak jailbreak protection make you liable — naval · 2026-09-13
- Radiation as a regulatory model for AI safety: no prior approval, just risk caps and certification — StrategicHarmony · 2026-09-13
- Musk backs Dario on AI oversight, floats competitor peer review as starting point — agihouse_org · 2026-09-13
- Open-model RL practitioner pushes back on roon: safety standardization won't threaten open source — willcb · 2026-09-13