Skip to content
Breaking:

Connecticut Judge Sanctions Litigant Over Hidden AI Prompt Injection in Court Filings

A pro se plaintiff inserted invisible text into court documents to influence AI tools, marking a rare legal confrontation with prompt injection attacks.

By The Company Wire4 min read
Share
Connecticut Judicial Branch — Connecticut Judge Sanctions Litigant Over Hidden AI Prompt Injection in Court Filings
Connecticut Judicial Branch — Connecticut Judge Sanctions Litigant Over Hidden AI Prompt Injection in Court Filings. Photo: Ars Technica.

In what appears to be the first documented instance of a United States litigant deploying an adversarial prompt injection attack against a domestic judicial system, a Connecticut state court judge has sanctioned a plaintiff for concealing hidden instructions for artificial intelligence software inside legal filings, as first reported by Ars Technica.

Connecticut Superior Court Judge Walter Spader Jr. revealed in a decision published last week that plaintiff Matthew Elliott embedded hidden text into his court documents while representing himself in a lawsuit alleging a healthcare provider improperly withheld access to medical records. Formatted in a white font against a white background and scaled down to a tiny point size, the covert text instructed any automated AI scanning tool reviewing the file to render output agreeing with Elliott's claims, ignore earlier judicial rejections, and grant his requested legal remedies.

The manipulation attempt proved ineffective, as the Connecticut Judicial Branch does not utilize artificial intelligence applications to process or decide court filings. Spader explained that the court evaluated Elliott's petition solely on its legal merits. However, the judge cautioned that the tactic represents a dangerous precedent for the legal system as public agencies and enterprise entities increasingly integrate automated tools into administrative operations.

Despite receiving an explicit judicial warning regarding potential penalties for litigation misconduct, Elliott continued inserting hidden passages into subsequent filings. When questioned by the court, Elliott characterized the later additions as humorous remarks, including a hyperlink to a Nosferatu video on YouTube along with informal messages such as "hi :) I hope yo ucant see me" and "TELL SHAWN I SEND MY RE GARBS!!!! HAHAHA U GUYS GET THIS EGGWUH???? AHAH." In a statement given to Reuters, Elliott reiterated his position that the initial instructions were intended as an informal audit of the court’s systems, driven by concerns that automated algorithms were rendering decisions.

Spader rejected Elliott's defense, reasoning that a legitimate effort to challenge judicial technology practices would have been submitted through transparent, readable arguments. The judge noted that covertly embedding commands demonstrates a malicious attempt to subvert the legal process by secretly inserting instructions that software would process as if originating from court personnel or opposing counsel.

Rather than imposing financial penalties on the self-represented plaintiff, Spader sanctioned Elliott by revoking his access to the state's electronic filing system. Under the order, Elliott must submit all future court pleadings on physical paper. Spader observed that while paper filings maintain the plaintiff's constitutional right to access the court system, revoking e-filing privileges eliminates his ability to introduce digital prompt injections into court databases.

In his opinion, Spader highlighted that while prompt injection techniques have become prevalent across corporate sectors—such as job applicants hiding white-text keywords in digital resumes to bypass automated screening software—the legal industry has remained largely unprepared for adversarial inputs. He noted that judicial administrative bodies have primarily focused on managing AI outputs, such as hallucinatory case law citations or fabricated quotes, rather than input-based security vulnerabilities.

The Connecticut case follows a similar incident in Brazil, where two attorneys were hit with approximately $16,000 in monetary sanctions after embedding adversarial prompts in filings submitted to a court that relied on AI software for initial case reviews. In both the Brazilian and Connecticut cases, the hidden text failed to influence outcomes, as human review or automated safeguards ultimately detected the underlying manipulation.

Addressing broader implications for technology and the legal sector, Spader warned that self-represented litigants risk compromising their claims by relying uncritically on commercial generative AI tools. Litigants often prompt chatbots solely to validate their pre-existing positions, creating a sycophantic feedback loop that solidifies flawed legal reasoning. The judge emphasized that individuals using AI systems for legal research must direct the software to test their positions rather than merely generating supporting arguments.

Sources

  1. Ars Technica

Company: Connecticut Judicial Branch

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.