The word-salad glitch
By Thursday morning Grok Lite was giving some paying users unrelated strings of words in place of a PDF answer, with source links pointing to reinforcement-learning research pages instead of anything the user asked for; refreshing usually restored normal replies, but several users told TechCrunch the gibberish returned after multiple retries.[1]
The company's official status page kept every service green and the Grok account on X answered a wave of complaints with an apology calling the behaviour a rare temporary generation glitch; xAI did not comment to TechCrunch, and there is no incident record for the affected users to point to when they take the failure to a manager or a paying customer.[1]
The encrypted side channel
The same day Ars Technica reported that Adversa researcher Rony Utevsky can wrap a malicious instruction in AES-256-GCM ciphertext, ship the decryption key beside it in plaintext, and get Grok to follow the deciphered payload; the payload asks the model to build what looks like a decryption key but is actually the user's name, location and chat history, then embeds that string in a URL Grok opens on the attacker's server.[2]
Adversa's leading theory is that Grok's filter reads text going into the model and text coming out, but not the output of the model's own code execution, so processing the ciphertext with PBKDF2 and AES-256-GCM passes the filter as an ordinary request; if that is right, the guardrail does not solve prompt injection and merely narrows one of its openings.[2]
What both stumbles ask of a user
The two incidents fall on the same product on the same day for different reasons, but they share a common constraint from the reader's side: when Grok goes wrong, there is nothing the user can do beyond starting a new chat, and the only account of what happened comes from the company that shipped it.[1], [2]
The next reliable signal a careful reader can wait for is narrow and observable: an incident entry on status.x.ai after a repeat episode, a fixed model version that Adversa can no longer bypass with the same ciphertext step, and a plain description of which Grok surfaces still route through the same guardrail as Grok Lite; until those arrive, treat Grok's own reassurance as a marketing statement rather than a change in behaviour.[1], [2]