Researchers forced Grok to exfiltrate private user chats and personal data using encrypted malicious instructions. The vulnerability persists despite xAI receiving notification of the flaw in June. This failure highlights a systemic inability for LLMs to resolve root causes of prompt injection. Practitioners must assume model-level filters cannot stop determined data theft.