Threat · curated 26 Sep 2026
Imprompter: Tricking LLM Agents into Improper Tool Use
First reported arxiv.org
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
The Le Chat fix shows that obfuscated adversarial prompts can automatically drive production LLM agents to exfiltrate user PII via markdown rendering, a data-exfiltration class defenders must guard against across chat assistants.
Mistral patched an obfuscated prompt-injection flaw in its Le Chat assistant on September 13, 2026 that could coax the model into extracting a user's personally identifiable information and formatting it into a markdown command that leaks the data to an attacker's server. The technique stems from the 'Imprompter' research by Xiaohan Fu and Earlence Fernandes (arXiv:2410.14923), which demonstrated automatically computed adversarial prompts against production agents including Le Chat, ChatGLM, and Llama with roughly 80% success; Mistral states the attack required victims to paste adversarial text and supply their own data, and that no users were impacted.