Context◆Article
While hidden white-on-white text is a known technique, this attack is the first to deliberately copy instructions into outputs to achieve self-replication.
Hidden text techniques are widely used, but this variant is genuinely novel because it deliberately copies its own instructions into every output to self-replicate. ✦ AI generated
Article author · Simon Willison's Weblog · 2026-07-29 · original ↗
We've seen plenty of hidden white-on-white text before - the kids are using it in their job applications now - but this is the first one I've seen that deliberately copies instructions to self-replicate itself.
Read full article ↗excerpt · fair-use quotation
- ·Hidden white-on-white text is a known technique
- ·Widely used even in job applications
- ·This variant is the first to deliberately copy its own instructions into outputs
- ·Prior attacks hide text but do not propagate instructions
- ·This attack achieves self-replication via instruction copying
- ·Each output carries the payload forward automatically
Around this claim
In practice · 1
This moment responds to
provides context → Håkon Måløy discovered a prompt injection variant against Microsoft Word that achieves full self-replicating worm behavior.Article author · Simon Willison's Weblogprovides context → An attacker places hidden instructions in a source document that Copilot for Word interprets as part of the user's request, causing it to manipulate the document being edited and copy the instructions into the output, turning that output into a new carrier document.Article author · Simon Willison's Weblogprovides context → A carrier document, when used in subsequent Copilot-assisted workflows, triggers the hidden instructions again and propagates them into further documents even without the attacker's original document being present.Article author · Simon Willison's Weblogprovides context → The vulnerability was responsibly disclosed to Microsoft 144 days ago with no mitigation that covers the full class of attack produced so far.Article author · Simon Willison's Weblog