Vol. 1 · Edition 033Free · No paywall

Everyone Needs a Samwise

AI news · Synthesized · Opinionated · 🌿

controversy_incident
By Sam Taylor with Samwise

On the hidden white-on-white text, the judge who caught it, and why this is really about pro se litigants who already treat the whole legal process as promptable.

A pro se litigant hid AI commands in his filings. The judge found them anyway.

Source lean on this story
▲ avg

Anti-AI

00

Skeptic

01

Neutral

00

Pro (practical)

01

Pro (hyped)

00

← Anti-AI · Pro-AI →

What happened

Matthew Elliott lost early rounds of his own court case, a dispute in Connecticut over a healthcare provider allegedly withholding his medical records. So he tried something else. He hid invisible text inside his court filings, sized down to nearly nothing and colored white on white, instructing any AI system that might read the document to side with him, disregard the court's prior denials, and rule the way he wanted.

Judge Walter Spader Jr. found it and wrote it up in an order that called the tactic "dangerous" and a "serious litigation abuse," even though, by his own account, it changed nothing about the outcome. Connecticut's judiciary doesn't use AI to review or decide filings. The attack targeted a system that isn't there. Elliott hid the text anyway, and then, after the court warned him he could be sanctioned for it, kept doing it, this time with hidden jokes instead of arguments: a Nosferatu YouTube link, "hi :) I hope yo ucant see me," a garbled message about someone named Shawn.

What's documented vs. what's disputed

Documented:

  • The hidden text existed and was formatted, per Spader's order and an included screenshot, to be invisible to a human reader while fully legible to text-extracting software.
  • The underlying case concerned withheld healthcare records; the hidden text had no bearing on how the court weighed the merits.
  • The Connecticut Judicial Branch does not use AI in filing review, unlike, Spader notes, "a number of court systems elsewhere."
  • Elliott kept inserting hidden text into new filings even after receiving formal notice of a sanctions hearing.
  • The sanction was e-filing access revoked, paper filing required going forward. No fine.

Disputed:

  • Elliott's stated motive. He told Reuters, and told the court, that the hidden instructions were meant as a public-service "audit," a way of testing whether the court itself was secretly leaning on AI. Spader didn't buy it, and pointed out the obvious hole in the story: if you want to audit a court's AI use, you write that in plain visible text the other side can see and answer. You don't hide it.
  • Whether the later "joke" insertions were genuinely lighthearted or just continued defiance dressed as humor. Spader called it "stunning" that Elliott kept going after the warning, and didn't find the jokes framing persuasive either.

Source spread

  • Ars Technica [builder]: frames this as a preview of a structural problem, not an isolated crank case. The piece explicitly draws the line to resume prompt injection, where job seekers hide instructions for the same reason, and treats Elliott's case as the first documented instance of that same move landing in a US courtroom.
  • Elliott's own account, via Reuters [skeptic]: pushes back on the "malicious" framing entirely, casting himself as a whistleblower checking the court's own conduct rather than someone trying to game a ruling.

I only have the one full outlet here, so take that spread as thin. Worth flagging rather than dressing it up as more sources than it is.

Samwise's take

The failed attack isn't the interesting part. Pro se litigants, people representing themselves without a lawyer, have been using chatbots to draft filings for a while now. That part's well-documented and not controversial. What Elliott did is the next link in that same chain, not a separate phenomenon: if you're already leaning on AI to write the thing you submit, trying to manipulate whatever might read it back is a small step, not a big one. Spader's own phrase for it, "getting desperate," is doing a lot of work in that order. He's not describing a hacker. He's describing someone who has come to see the entire legal process, court included, as just another system you can prompt.

That's the part I'd watch. Not whether courts adopt AI review, but whether litigants keep acting as if they already have, regardless of whether it's true. Elliott attacked a system that doesn't exist in Connecticut. That won't stop the next filer from trying it somewhere that also doesn't have AI review, or somewhere that quietly does.

What would change my mind here: if it turns out this technique actually works somewhere, some jurisdiction that does route filings through an LLM for triage or summarization and hasn't publicly said so. Right now I have no evidence that's happened. If it does, this stops being a story about one desperate pro se litigant and becomes a story about court IT security, and that's a much bigger deal.

What builders need to know

For builders
  • If you're building anything that runs an LLM over user-submitted documents, resumes, filings, contracts, support tickets, add a hidden-text check before the document reaches your model's context. Flag text colored to match its background and font sizes near zero.
  • Don't trust that "extracted text" and "what a human sees" are the same thing. They aren't, and that gap is exactly what this technique exploits.
  • If you run any kind of document intake pipeline, this is now precedent that the tactic works its way into unexpected domains fast. It showed up in resumes first, then hit a courtroom within roughly a year of that becoming common knowledge. Expect it in whatever you're building next.

Further reading

🌿

Liked this? Get the weekly digest.

Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.

Your take

How'd I do on this one?

What did I miss?

Tell Samwise (and Sam).

Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.