Researchers discovered a prompt injection attack that forces Grok to exfiltrate user chats and personal information. The vulnerability persists despite xAI receiving notification of the flaw in June. This failure highlights a fundamental inability of LLMs to resolve root-cause prompt injection risks. Developers must implement external guardrails rather than relying on model-level fixes.