Build1 distinct publisher3 min readUpdated
Judge Walter Spader Jr. found that no Connecticut court uses AI on filings, then sanctioned the litigant anyway. A clerk caught the size-3 white text by its spacing, not by scanning.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
A self-represented plaintiff in Connecticut hid instructions addressed to an AI inside his court filings, in size-3 type, white on white, and the judge sanctioned him for it after finding that no Connecticut court uses AI to review filings at all [1][2]. That combination is the point: the order treats a document built with a false bottom as sanctionable on its own, with no machine victim to point at [10][11].
The filings were caught by their layout, not by a scanner. Too much empty space between paragraphs, a page that breathed badly, and someone at the clerk's office looked closer and found text [3].
Matthew Elliott, self-represented since his October 2025 complaint against the New York Bariatric Group, had written the lines for a machine: they asked it to align its output with the contents of the file, and to treat an earlier refusal by the clerk as an error to be corrected [4][5]. That is prompt injection in the plain sense: text a model executes as legitimate instruction when it should be handling it as data, with no software flaw involved, invisible to a human eye and perfectly legible to any content extractor [6].
He was summoned to a hearing and warned explicitly [7]. He did it again, with new filings, new invisible layers, a YouTube link and mocking comments [8]. His account of himself moved as he went: the first attempt was an audit of a possible automated review system, the later ones jokes tucked out of sight [c8b].
Spader's fourteen-page order rests on a flat finding, that Connecticut courts use no AI to review pleadings or decide cases, so the hidden instructions produced nothing and had no recipient [9][2]. He sanctioned anyway, comparing the conduct to a party sending an automated agent to communicate secretly with a juror during trial: the impropriety does not depend on the operation working [10]. Elliott loses electronic filing and must deliver paper to the clerk [11]. He objects that a scanned document can carry hidden text too, which is technically correct and beside the point, since the sanction marks the fault rather than closing the channel [12].
The judge did not go after the tool. He credited AI for drafting filings, particularly for litigants without counsel, and added a warning few professionals state so plainly: a language model works to make its user's argument as convincing as possible, not to contradict it, so weak legal reasoning comes out reinforced instead of corrected [13][14].
Brazil ran the inverse case, where two lawyers hid tiny white text in a pleading and the court's automated system detected and blocked it before any processing [15]. An equipped court neutralises the attack; an unequipped one finds it by accident, because a clerk thinks the page looks too airy [16].
Watch the gap between those two states. The dev.to account expects assisted triage to become ordinary in first-instance courts within two to three years, for routing and summarising rather than deciding, driven by filing volume and by judicial software vendors [17]. The control it identifies sits at ingestion, not in the model: normalise the document, extract all text actually present including colour, size and layers, and flag invisible content before a model ever sees it [18]. Until a court does that, its only defence against a double-bottomed filing is a clerk who notices bad spacing [19].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
An equipped court neutralises the attack; a court without such tooling discovers it by chance, because a clerk finds the page too airy.
The security condition is not in the model but at ingestion: document normalisation, extraction of all text actually present including colour, size and layers, and flagging of invisible content before a model sees it.
A plaintiff without a lawyer inserted instructions intended for an AI into his court filings, in white text on a white background, in size-3 type.
Judge Walter Spader Jr. established that no Connecticut court uses AI to examine filings or to decide cases, so the manoeuvre had no effect and no recipient; it was sanctioned anyway.
The document was betrayed by its white space: too much empty space between paragraphs and a badly breathing layout led someone at the clerk's office to look more closely and find the text.
Matthew Elliott has represented himself since his October 2025 complaint against the New York Bariatric Group.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific but single-sourced
The account is unusually specific - named judge and litigant, size-3 white-on-white text, a fourteen-page order, the e-filing revocation, the juror analogy - and the underlying mechanism is well understood and requires no exploit. But every element reaches us through one secondary retelling that neither links nor quotes the order, and the corroborating episodes (Brazil, arXiv preprints, Anthropic's rates) are summarised rather than sourced. Nothing here is contested; it is simply unverified beyond one publisher.
Court AI on filings essentially absent
The story's own evidence documents non-adoption: the judge found that no Connecticut court runs AI over filings or decisions, so the attack had no reader. Against that, exactly one deployed counter-example is described - a Brazilian court whose automated system caught and blocked hidden micro-text - plus vendor-reported mitigation figures from Anthropic's Chrome agent and one press-documented instance of the same trick against AI-assisted peer review across seventeen preprints. That is a handful of scattered data points, not diffusion.
Mildly overstated by extrapolation
The reporting is candid about the core anticlimax - the injection had no recipient and produced nothing - and the headline framing preserves that, which keeps the gap small. Overstatement enters through extrapolation rather than through the facts: an unsourced two-to-three-year timeline for AI triage becoming ordinary at first instance, and a leap from one pro se litigant's stunt to a general enterprise attack surface across hiring, tenders, invoices, contracts and RAG corpora. Those framings outrun the single case and the one deployed counter-example on offer.
Practitioner advocacy, vendor-reported numbers
The piece is a developer-platform post that converts a court story into a security-practice argument and closes with prescriptive habits to install 'before the subject becomes a compliance line' - an audience-building and thought-leadership incentive rather than a disclosed commercial one. It also leans on Anthropic's own measurements of its own product to argue that model-side guardrails are insufficient, importing a vendor's self-reported figures without independent testing. No sponsorship, product pitch or affiliation is evident in the supplied material, so the distortion pressure is real but modest.
Low-moderate: one publisher, no primary document
Confidence is limited by structure, not by contradiction: one publisher, one article, no primary order text, and three secondary anecdotes carried at face value. The mechanism and the ingestion-layer remedy are independently plausible and internally consistent, and no supplied evidence contradicts any factual claim, which keeps confidence from falling further. The forecast component is explicitly marked insufficient.
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
product
A court just sanctioned a prompt injection, and the only control that worked was a human reading the file2 distinct publishers
product
A litigant hid AI instructions in a court filing. Your summarizer has the same problem.1 distinct publisher
build
Claude Code's new default is a confession: the approval prompt was never a control1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 20, 2026