ASCII Smuggling

Unicode includes characters that render as nothing on screen but are still processed by many language models. Attackers use them to hide instructions in otherwise normal-looking text, or to tuck stolen data into links and outputs.

ASCII smuggling is used for:

  • Hidden instructions: Invisible prompts embedded in documents, emails, or web pages.
  • Data exfiltration: Encoding stolen data invisibly inside URLs or responses.
  • Filter evasion: Bypassing keyword-based security filters.
  • Phishing evasion: Hiding malicious content from email security scanners.
  • Poisoned code: Invisible text in files read by coding agents.

Researchers demonstrated ASCII smuggling against several major AI assistants, and in 2026 Microsoft reported attackers adapting the technique to evade phishing detection, showing how AI attack methods spread to other threats.

Defenses include stripping or flagging invisible Unicode in inputs and outputs and rendering hidden characters visibly during review.

How PointGuard AI Helps

PointGuard AI AI Runtime Guardrails normalize and inspect inputs and outputs for invisible Unicode and hidden instructions, and AI Data Protection detects encoded data leaving AI workflows.

Learn More

Watch Blog Video

Follow us on LikedIn

Our Newsletter

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.