Winzheng, a researcher at Microsoft, put it plainly: “Because tag characters are invisible to humans but exist at the text-processing level, the same property that makes them useful for smuggling instructions into a model also makes them useful for obfuscating malicious content.” That’s the whole story in one sentence. A technique I’ve spent the last year warning people about
What ASCII smuggling actually is
Let’s strip the jargon out. ASCII smuggling hides text inside invisible Unicode characters. To your eyes, an email looks clean. To a spam filter or an AI model parsing that message, there’s a second layer of content sitting right there in the character stream. It’s not a vulnerability you can patch with an update. It’s an abuse of how text processing works at the fundamental level.
I’ve covered this trick when it was being used to slip malicious instructions past AI guardrails. Attackers would hide a cters in input” as a question worth asking. The spammers are already asking it.
đź•’ Published: