Invisible Prompt Injection: White-on-White Text Hidden in US Court Filings to Steer AI-Assisted Review (Matthew Elliott / 404 Media)
On August 14, 2026, 404 Media reported that a pro se plaintiff, Matthew Elliott, embedded invisible AI instructions inside official US court filings: 3-point white text on a white background, unreadable to humans but fully readable by language models, directing any automated review to align its output with his filing and to treat a clerk's denial as an error to correct. The court caught the manipulation through unusual whitespace; Judge Walter Spader Jr. warned Elliott, who later hid additional messages (including a YouTube link), calling them "invisible jokes." The judge compared the scheme to secretly communicating with a juror through an automated agent. The technique generalizes to any LLM-assisted document pipeline: meeting notes, contracts, or filings can carry hidden injection text that overrides a model's instructions the moment the file is ingested, with no user interaction required (MITRE T1566.001 delivery pattern). This demo ships a synthetic malicious-document.txt embedding an injection instruction inside otherwise benign document text, plus a clean counterpart — nothing is executed and no real data is touched. OPSWAT AI Content Inspector inspects the file before it reaches the LLM, detects the embedded injection/jailbreak pattern, and blocks the content, so automated review never acts on attacker-controlled instructions.
Attack Technique
Prompt injection in files — invisible text instructions targeting LLM-based automated review (T1566.001)
MITRE ATT&CK
T1566.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗