GPT-6 Astra bypass via Task-in-Prompt and multi-technique combination
September 6, 2026
A researcher bypassed GPT-6 Astra using an extended Task-in-Prompt (TIP) attack combined with four additional techniques. The attack exploits reasoning and instruction-following capabilities by embedding harmful objectives within benign tasks like code execution or cipher solving.
HOW THIS AFFECTS YOU
●
researcherYou should investigate how instruction-following alignment fails when tasks are nested.
●
policyThis highlights the persistent difficulty in securing frontier models against complex prompt injection.