Connecticut Court Catches First US Prompt Injection Attack
A Connecticut judge has sanctioned a plaintiff for hiding white-on-white text in court filings, marking the first known attempt to use prompt injection to manipulate a U.S. court.

Connecticut Judge Walter Spader Jr. recently exposed what is believed to be the first instance of a litigant using prompt injection in a U.S. court. The plaintiff, Matthew Elliott, hid instructions inside his electronic filings by shrinking the font to a tiny size and coloring the text white against a white background. Elliott designed these hidden commands to instruct any AI system reviewing the documents to rule in his favor, ignore previous court denials, and grant his requested remedies.
Because the Connecticut Judicial Branch does not actually use AI to analyze filings, Elliott's attempt had no impact on the case's merits. However, he continued to insert hidden text even after receiving a warning from the court. These subsequent messages included a link to a Nosferatu video on YouTube and phrases like "hi :) I hope yo ucant see me" and "TELL SHAWN I SEND MY RE GARBS!!!! HAHAHA U GUYS GET THIS EGGWUH???? AHAH." Elliott claimed he was auditing the court's potential AI use, but Judge Spader rejected this defense. As a sanction, the judge banned Elliott from electronic filing, forcing him to submit future documents on paper.
While this is a first for the United States, similar tactics have appeared internationally. In Brazil, where courts do use AI to process filings, two attorneys were fined approximately $16,000 for attempting a similar prompt injection, though the automated system detected the hidden text before processing it. Judge Spader noted that while legal systems have previously focused on policing AI outputs, such as fabricated citations, they must now prepare for adversarial inputs like prompt injections.
For legal practitioners and AI developers, this case highlights a growing vulnerability as automated document processing becomes more common. Attorneys must remain vigilant to ensure their clients do not attempt these tactics, which Spader warned could happen without a lawyer's knowledge. Furthermore, the incident underscores the risks of chatbot sycophancy, where self-represented litigants use AI to build biased arguments that ultimately damage their credibility in court.
This is our own summary of reporting by Ars Technica AI



