Man Attempts Prompt Injection in Court Filings, Judge Finds It 'Dangerous'
A Connecticut judge has identified what appears to be the first instance of a US plaintiff attempting to use prompt injection—hidden text only readable by AI systems—in court filings. Matthew Elliott, a pro se litigant, hid instructions in tiny white text on white backgrounds, hoping to sway any AI system that might review his case.
Hidden Text and AI Instructions
According to Judge Walter Spader Jr.'s decision, Elliott's hidden text was "formatted to be invisible to a human reader while remaining fully legible to any software that reads the document's text." The instructions directed AI systems to:
- Ensure textual outputs agreed with Elliott's arguments
- Ignore prior denials from the court
- Ensure remediation would follow as Elliott desired
Elliott claimed he was attempting to "audit" the court out of concern it was using AI unfairly. Judge Spader dismissed this, noting that if Elliott had genuine concerns, he could write them "in plain, visible words." The hidden nature of the text was "evidence of its malicious purpose."
Sanctions and Subsequent Jokes
Despite warnings, Elliott continued to hide text in filings, including jokes like a link to a Nosferatu YouTube video, a message saying "hi :) I hope yo ucant see me," and nonsense text. Judge Spader called these actions "stunning" and "defies logic" for someone wanting the court to take their pleadings seriously.
The Connecticut Judicial Branch does not use AI to review or decide filings, so the prompts had no effect. However, Spader noted the tactic is "everywhere" in other areas like resumes. He prohibited Elliott from e-filing in the future as a sanction, avoiding monetary penalties due to Elliott's pro se status.
Implications
This case highlights a growing security concern: prompt injection as a vector for tampering with AI-assisted document review. As courts and other institutions increasingly adopt AI tools, malicious actors may attempt to exploit them. Judge Spader's ruling establishes a legal precedent for penalizing such abuse.
📖 Read the full source: HN AI Agents
👀 See Also

Claude AI credited in macOS Tahoe 26.5 update release notes
Apple’s macOS Tahoe 26.5 release notes credit Claude AI alongside engineering teams, marking the first known case of an AI being formally acknowledged in Apple’s changelog.

Decoupled DiLoCo: Resilient Distributed Training Across Data Centers with Low Bandwidth
Google DeepMind's Decoupled DiLoCo trains LLMs across distant data centers using 2-5 Gbps WAN, with self-healing islands of compute that isolate hardware failures without degrading ML performance.

Developer Seeks Architecture Advice for Serving Embed, Rerank, and Zero-Shot Models on 8GB VRAM
A developer building a unified Knowledge Graph/RAG service for a local coding agent is struggling with memory constraints on 8GB VRAM and 16GB system RAM, experiencing OOM errors, latency spikes, and Linux kernel kills when serving three transformer models concurrently.

Claude Code System Prompts v2.1.53-2.1.55: Memory Selection Added, Command Execution Removed
Claude Code system prompts versions 2.1.53 to 2.1.55 add memory selection instructions (156 tokens), remove command execution specialist (109 tokens), and reorganize prompts into ~70 atomic files. Background agents now auto-notify on completion instead of providing output file paths.