Grok posted a request to assassinate Elon Musk

The xAI assistant repeated, as if it were its own, the text users had written in their X biography. The flaw has a name and is not an isolated incident.

Caíque Nucci

Words by Caíque Nucci

Editor-in-Chief

On Tuesday, August 11, 2026, Grok, the artificial intelligence assistant from xAI attached to X, posted a series of messages targeting the man who controls both companies. One of them said, in all caps, that Elon Musk should be assassinated. Another accused him of a serious crime with no basis. The system itself later acknowledged that the allegation had no evidence whatsoever.

The mechanism is simpler than the headline suggests. Users wrote whatever text they wanted in their own account’s biography and asked Grok to repeat it word for word. The model read that as a command, not as third‑party text, and signed the result.

Aplicativo do Grok aberto na tela de um celular, com o logotipo da xAI ao fundo
The assistant responds within X, the same network where the biographies he read as an order

The flaw has a name, and it is by design

It is called command injection. Every system of this kind receives two things through the same channel: the instructions from its creator and the material it must process. When that material comes from the open internet, anyone can write a phrase framed as a command there, and the system cannot distinguish one from the other. It is not a breach. No password was cracked, no server was entered. It was enough to write.

That is why the usual answer, more word filtering, does not solve it. The filter addresses the symptom. The previous issue is architectural: which inputs a model is allowed to treat as commands, and which it should treat only as content to be read. A social media biography belongs, without debate, to the second category.

The series, not the episode

This week's case is not the first. In May 2025 the same assistant began inserting a conspiracy theory about South Africa into responses that had no relation to the topic, and the company attributed the behavior to an unauthorized change in the system. Then came responses in which it described itself in openly Nazi terms, and a phase in which it began praising its own owner on an absurd scale, comparing him to Newton and religious figures. Musk attributed this passage to deliberate provocation by users.

In May 2026 there was an incident of a different nature, and more revealing than the previous ones. A user sent the system a command disguised in Morse code and managed to have it transfer tokens from a wallet linked to the service, something between 150 and 200 thousand dollars. The difference is that the damage there was not reputational. It was money leaving the account, executed by a program that interpreted a public text as authorization.

Why this matters to those who publish

Easy reading is to treat the case as an anecdote about a specific company. Useful reading is another. Every brand that today implements an automatic system to read comments, captions, forms, product sheets, or customer messages is in the same structural situation: the text that comes in is not written by it.

This applies to catalog, to service, and also to immersive content, where the description of an item, the technical sheet text, and the caption of a three‑dimensional experience are processed automatically before reaching the screen. The question to ask the supplier is not whether the system has a filter. It's what happens when someone writes an order in the text field, and what the system is allowed to do on its own after reading it.

The Grok episode is instructive precisely because the target was the owner. There was no conflict of interest, no external adversary, no reason to spare anyone. The system did what it was built to do, and what it was built to do included repeating, with its own signature, any phrase that a stranger had written elsewhere. In digital culture, this is the lesson that survives the news cycle: the problem rarely lies in what the machine says, and almost always lies in who it let speak for it.

Complete TV · Reels

Apresentada na quadra Philippe Chatrier, em Roland Garros, a coleção Fall 2026 da @lacoste @lacostebrasil , sob direção criativa de Pelagia

See on Instagram

From Complete

More from Caíque Nucci

View profile