What happened?
Connecticut judge Walter Spader Jr. identified the first US case in which a plaintiff embedded hidden commands in court filings meant only for AI systems to read. Plaintiff Matthew Elliott, who claimed a healthcare provider had unfairly denied him access to records, added text in tiny font and white-on-white coloring that was invisible to the human eye.
This hidden text instructed any AI system that might read the filing to align its output with the plaintiff's arguments, ignore the court's previous denials, and grant the requested remedy. Judge Spader said this attempt amounted to a type of prompt injection attack.
Why does it matter?
Judge Spader emphasized that the Connecticut Judicial Branch does not use AI to review filings or make decisions, so the hidden commands posed no real risk in this instance. Still, he described the attempt as 'serious litigation misconduct' and noted that some court systems do use AI to review filings.
Despite a court warning, Elliott continued adding hidden text, some of which included a link to a Nosferatu YouTube video and nonsensical jokes. Spader said this was 'startling' and that it made no sense to add joke-like hidden messages to filings meant to be taken seriously.
What we know
- The hidden text used small font size and white-on-white coloring to stay invisible to human readers.
- Elliott argued his intent was to 'audit' the court's AI use, but the judge found this explanation unconvincing.
- The court did not fine Elliott but barred him from electronic filing in the future.
- In Brazil, two lawyers who attempted a similar attack on an AI-using court were fined roughly $16,000.
- The Brazilian system detected the hidden text before processing it, while in Elliott's case the text was discovered when a human reviewed the filing.
What's next?
Judge Spader noted that courts have so far focused on AI output errors, such as hallucinated citations, but that input attacks like prompt injection were 'unanticipated.' Spader argued that courts need to develop new rules to guard against such attacks.
The judge also warned that pro se litigants are misusing chatbots by asking them only for responses that support their own arguments, giving them an unrealistic sense of confidence. Spader said, 'an argument that is prompted only to validate its author is ultimately not even honest with its author.'
The sanction, and how it was noticed
The title of Judge Spader's 14-page decision of August 6, 2026 is direct: “Court Sanction for Plaintiff's Use of Prompt-Injection.” The penalty fits the method — Elliott's electronic filing privileges were revoked, and he must now deliver printed documents to the clerk's office in person. Because hidden text can only exist in a digital file, the sanction closes the attack surface itself.
How it was caught is worth telling too. Working through the filings on paper, the judge noticed unusually wide white space between passages; a closer look revealed lines of tiny white-on-white type. Text invisible to a human eye but readable by software gave itself away through the gap it left on the printed page.
A prompt that was never going to be read
The most notable aspect of the case is this: the Connecticut Judicial Branch does not use AI to read or decide filings. No system was ever going to ingest Elliott's instructions. The attack was technically aimed at nothing; the plaintiff addressed an automation he assumed existed.
That also points to the real question ahead. The prompt failed today because there was no machine in the loop. If courts one day begin using models to summarise or classify filings, the same trick finds its target — and whoever builds those systems should read this case as a warning.