---
title: "First-ever US case of 'hacking' a court via AI: how hidden text in documents led to sanctions"
description: "🚨 The first attempt to \"hack\" a court via AI has been recorded in the US. A plaintiff in Connecticut hid instructions for neural networks in documents to force them to rule in his favor. The judge imposed sanctions: a ban on electronic document filing. Experts warn of a new threat—attacks on AI input data. #AI #Court #Cybersecurity #Connecticut"
date: 2026-08-16T20:48:48.000Z
lang: en
url: https://xab.info/en/posts/first-ever-us-case-of-hacking-a-court-via-ai
tags: [artificial-intelligence, law, cybersecurity, usa, prompt-injection, court-ruling]
publisher: "XAB.info"
---

# First-ever US case of 'hacking' a court via AI: how hidden text in documents led to sanctions

![Judge in courtroom reviewing documents; monitor displays text with label 'AI Adopts Personal Bias Detected' — illustrating first U.S. case of court 'hacked' via AI](https://xab.info/media/2026/08/17/perviy-sluchay-vzloma-suda-cherez-ii-v-ssha/perviy-sluchay-vzloma-suda-cherez-ii-v-ssha-1.webp)

## 🎯 Key Points

- A Connecticut judge imposed sanctions on a plaintiff for hidden AI instructions in court documents.
- The technique of prompt injection was used: the text was invisible to humans but readable by machines.
- This is the first recorded case in the US of an attempt to manipulate the judicial system via AI.
- The plaintiff was deprived of the right to file documents electronically and must submit papers in person.
- The judge warned about the danger of using chatbots to build arguments without fact-checking.

### A new form of procedural fraud: an attack on neural networks

A precedent-setting case has been recorded in US judicial practice, which may become a turning point in the regulation of artificial intelligence use in the legal field. On August 6, 2026, Connecticut Supreme Court Judge Walter Spader Jr. issued a ruling imposing sanctions on a plaintiff for attempting to manipulate the judicial system using hidden AI instructions. The incident, dubbed the "first identified case of its kind in the US," demonstrates how technologies designed to simplify lawyers' work can be exploited to circumvent procedural norms.

The essence of the violation lay in the use of a technique known as "prompt injection." The plaintiff, Matthew Elliott, concealed text in his motions filed on July 24 that was invisible to the human eye but readable by software algorithms. The text was typed in white font, only 3 points in size, on a white background. The hidden commands contained instructions for any AI system analyzing the case materials: to support the plaintiff's position, ignore previous court rejections, and formulate a conclusion in favor of the requested ruling.

### Court verdict and the nature of the attack

Judge Spader classified Elliott's actions as "serious abuse of procedural rights." In his ruling, he detailed the mechanism of the attack: the perpetrator attempted to inject a command into the data stream that the system receives from the court or process participants. The goal was to make the AI perceive the document author's instruction as a legitimate command from the system operator—whether that be the court, its staff, or the opposing party.

It is important to note that there was no immediate threat to the outcome of the case. The Connecticut judicial system does not currently use AI to analyze materials or render decisions in such cases. However, the very fact of the attempted manipulation was deemed unacceptable. Spader emphasized that until now, courts' focus on AI use had been centered on errors in its responses—fabricated citations and "hallucinations." In this instance, the reverse problem arose: the perpetrator attempted to manipulate not the AI's output, but its input data.

### Escalation of conflict and sanctions

The situation was exacerbated by the fact that after the initial warning, Elliott continued to add hidden text to new documents. He referred to subsequent messages as "jokes": among them were a link to a "Nosferatu" video, a short greeting "hi :) I hope yo ucant see me," and a nonsensical string of words. The judge considered the continuation of such behavior after a warning as a separate ground for sanctions.

As punishment, Spader did not impose a monetary fine. Instead, Elliott was banned from using the electronic document filing system. Henceforth, he is required to personally submit motions and attachments on paper through the court clerk's office. This decision underscores the court's seriousness: trust in digital filing channels has been lost regarding this particular participant in the proceedings.

### The problem of "reverse argumentation" and the role of chatbots

Spader also linked this incident to the broader issue of chatbot use by individuals representing themselves in court (pro se litigants). In his observation, unrepresented participants often construct arguments "in reverse": they first convince the AI model of their own correctness, then ask it to defend the already chosen position, without forcing the system to verify facts or present arguments from the opposing side.

The judge considers this a dangerous trend, as chatbots' tendency to agree with the user can reinforce an erroneous position rather than verify it. Similar attacks to the one attempted by Elliott have already been used in other fields; therefore, courts will likely have to account for them separately and develop new security protocols for processing digital documents.

## ❓ FAQ

### Q: What is prompt injection in the context of a court?
**A:** It is a hidden instruction within input data (documents) designed to alter AI behavior. In this case, the text was invisible to humans but contained commands for the neural network.

### Q: What sanctions were applied to Matthew Elliott?
**A:** He was banned from using the electronic document filing system. He is now required to personally submit motions on paper through the court clerk's office.

### Q: Did the attack affect the outcome of the case?
**A:** No, the Connecticut judicial system does not use AI to render decisions, so there was no immediate threat to the case outcome.