Man Attempts Prompt Injection in Court Filings, Judge Finds It 'Dangerous'

✍️ OpenClawRadar📅 Published: August 16, 2026🔗 Source
Ad

A Connecticut judge has identified what appears to be the first instance of a US plaintiff attempting to use prompt injection—hidden text only readable by AI systems—in court filings. Matthew Elliott, a pro se litigant, hid instructions in tiny white text on white backgrounds, hoping to sway any AI system that might review his case.

Hidden Text and AI Instructions

According to Judge Walter Spader Jr.'s decision, Elliott's hidden text was "formatted to be invisible to a human reader while remaining fully legible to any software that reads the document's text." The instructions directed AI systems to:

  • Ensure textual outputs agreed with Elliott's arguments
  • Ignore prior denials from the court
  • Ensure remediation would follow as Elliott desired

Elliott claimed he was attempting to "audit" the court out of concern it was using AI unfairly. Judge Spader dismissed this, noting that if Elliott had genuine concerns, he could write them "in plain, visible words." The hidden nature of the text was "evidence of its malicious purpose."

Ad

Sanctions and Subsequent Jokes

Despite warnings, Elliott continued to hide text in filings, including jokes like a link to a Nosferatu YouTube video, a message saying "hi :) I hope yo ucant see me," and nonsense text. Judge Spader called these actions "stunning" and "defies logic" for someone wanting the court to take their pleadings seriously.

The Connecticut Judicial Branch does not use AI to review or decide filings, so the prompts had no effect. However, Spader noted the tactic is "everywhere" in other areas like resumes. He prohibited Elliott from e-filing in the future as a sanction, avoiding monetary penalties due to Elliott's pro se status.

Implications

This case highlights a growing security concern: prompt injection as a vector for tampering with AI-assisted document review. As courts and other institutions increasingly adopt AI tools, malicious actors may attempt to exploit them. Judge Spader's ruling establishes a legal precedent for penalizing such abuse.

📖 Read the full source: HN AI Agents

Ad

👀 See Also