Skip to content

Build1 publisher3 min readPublished

Connecticut judge sanctions hidden prompt injection that no court AI was there to read

Judge Walter Spader Jr. found that no Connecticut court uses AI on filings, then sanctioned the litigant anyway. A clerk caught the size-3 white text by its spacing, not by scanning.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Connecticut judge sanctions hidden prompt injection that no court AI was there to read
Photo: yahoo.com

What happened

  • A plaintiff without a lawyer inserted instructions intended for an AI into his court filings, in white text on a white background, in size-3 type.
  • Judge Walter Spader Jr. established that no Connecticut court uses AI to examine filings or to decide cases, so the manoeuvre had no effect and no recipient; it was sanctioned anyway.
  • The document was betrayed by its white space: too much empty space between paragraphs and a badly breathing layout led someone at the clerk's office to look more closely and find the text.
  • Matthew Elliott has represented himself since his October 2025 complaint against the New York Bariatric Group.
  • The hidden lines asked the machine to align its output with the contents of the case file and to treat an earlier refusal by the clerk as an error to be corrected.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

A self-represented plaintiff in Connecticut hid instructions addressed to an AI inside his court filings, in size-3 type, white on white, and the judge sanctioned him for it after finding that no Connecticut court uses AI to review filings at all [1][2]. That combination is the point: the order treats a document built with a false bottom as sanctionable on its own, with no machine victim to point at [10][11].

The filings were caught by their layout, not by a scanner. Too much empty space between paragraphs, a page that breathed badly, and someone at the clerk's office looked closer and found text [3].

Matthew Elliott, self-represented since his October 2025 complaint against the New York Bariatric Group, had written the lines for a machine: they asked it to align its output with the contents of the file, and to treat an earlier refusal by the clerk as an error to be corrected [4][5]. That is prompt injection in the plain sense: text a model executes as legitimate instruction when it should be handling it as data, with no software flaw involved, invisible to a human eye and perfectly legible to any content extractor [6].

He was summoned to a hearing and warned explicitly [7]. He did it again, with new filings, new invisible layers, a YouTube link and mocking comments [8]. His account of himself moved as he went: the first attempt was an audit of a possible automated review system, the later ones jokes tucked out of sight [c8b].

Spader's fourteen-page order rests on a flat finding, that Connecticut courts use no AI to review pleadings or decide cases, so the hidden instructions produced nothing and had no recipient [9][2]. He sanctioned anyway, comparing the conduct to a party sending an automated agent to communicate secretly with a juror during trial: the impropriety does not depend on the operation working [10]. Elliott loses electronic filing and must deliver paper to the clerk [11]. He objects that a scanned document can carry hidden text too, which is technically correct and beside the point, since the sanction marks the fault rather than closing the channel [12].

The judge did not go after the tool. He credited AI for drafting filings, particularly for litigants without counsel, and added a warning few professionals state so plainly: a language model works to make its user's argument as convincing as possible, not to contradict it, so weak legal reasoning comes out reinforced instead of corrected [13][14].

Brazil ran the inverse case, where two lawyers hid tiny white text in a pleading and the court's automated system detected and blocked it before any processing [15]. An equipped court neutralises the attack; an unequipped one finds it by accident, because a clerk thinks the page looks too airy [16].

Watch the gap between those two states. The dev.to account expects assisted triage to become ordinary in first-instance courts within two to three years, for routing and summarising rather than deciding, driven by filing volume and by judicial software vendors [17]. The control it identifies sits at ingestion, not in the model: normalise the document, extract all text actually present including colour, size and layers, and flag invisible content before a model ever sees it [18]. Until a court does that, its only defence against a double-bottomed filing is a clerk who notices bad spacing [19].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories