Check Point Research disclosed PuzzleMask, a prompt-obfuscation technique that conceals policy-violating instructions within benign-looking prose. In tests of 23 crafted prompts, four resource-constrained LLM gatekeepers marked every wrapped prompt safe even though they blocked the corresponding plaintext payloads. A GPT-5 reasoning model with Python access recovered and acted on the hidden instruction in 17 of 18 cases; researchers stressed that the wrapper is not itself a jailbreak of the target model.
The technique extends the risk posed by indirect prompt injection in LLM-integrated applications: safety controls that inspect inputs in isolation can miss instructions encoded in content subsequently interpreted by a more capable model. Organizations should not rely solely on front-end prompt filtering; they should paraphrase or normalize inputs before screening, strengthen gatekeeper policies against encoded instructions, and monitor downstream model outputs, tool calls, and other agent actions for unsafe behavior.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Check Point researchers contacted Anthropic, Meta, and OpenAI with their findings and offered access to the obfuscated prompts, target tool calls and responses, and wrapper-generation pipeline.
Check Point Research described PuzzleMask, a prose-based prompt-obfuscation technique that caused all tested gatekeeper trials to classify crafted prompts as safe. In controlled tests, GPT-5 Thinking High recovered and acted on concealed payloads in 17 of 18 trials; the researchers also proposed paraphrasing, quantitative self-reference detection, and output/tool-action monitoring as mitigations.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcecyberveille.ch
Open sourcemalware.news
Open sourceresearch.checkpoint.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.