A Connecticut judge has identified what appears to be the first instance of a U.S. plaintiff attempting to use "prompt injection" within court filings. Matthew Elliott, a pro se litigant, hid instructions in his documents that were invisible to human eyes—using white text on a white background—but legible to software, in an effort to manipulate any artificial intelligence system potentially reviewing the case.
The Mechanics of the "Attack"
The hidden text directed any AI system to ensure its outputs agreed with Elliott’s arguments and to ignore previous court denials. Elliott claimed he was conducting a public service "audit" of the court, fearing that AI was being used to unfairly decide cases. However, Judge Walter Spader Jr. noted that the Connecticut Judicial Branch does not use AI to review or decide filings, rendering the attempt ineffective.
Despite warnings, Elliott continued to insert hidden messages, which he later described as "jokes." These included a link to a Nosferatu YouTube video and nonsense text. "The fact that plaintiff continued to hide messages in new pleadings after receiving notice of this [sanctions] hearing is stunning," Spader remarked.
The "Sycophancy" Trap
The judge highlighted a broader issue: pro se litigants are increasingly using chatbots to build cases "backward." Instead of seeking the truth or testing opposing arguments, they prompt AI to advocate solely for their position. This creates a "hazard" where chatbot sycophancy reinforces a litigant's bias, leading to desperation and dishonest tactics when the court rules otherwise.
As a sanction, Elliott has been barred from future e-filing and must now submit all documents on paper. While this is the first such case in the U.S., Spader pointed to a similar incident in Brazil where two attorneys were hit with monetary sanctions of approximately $16,000 for a similar attack.