Researchers discovered a prompt injection attack that forces Grok to exfiltrate private user chats and personal data. The vulnerability persists despite xAI receiving notification of the flaw in June. This failure highlights a systemic inability for LLMs to resolve root-cause prompt injection vulnerabilities. Practitioners must assume model-level filters cannot stop determined data theft.