TextAttack appears as an adversarial technique/toolset that leverages specially crafted prompts or tokens—named EchoGram tokens (e.g., '=coffee')—to flip AI guardrail verdicts and bypass safety filters.
TextAttack is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 14, 2025; most recent activity November 15, 2025.
TextAttack appears as an adversarial technique/toolset that leverages specially crafted prompts or tokens—named EchoGram tokens (e.g., '=coffee')—to flip AI guardrail verdicts and bypass safety filters. This exposes vulnerabilities in AI guardrails and content moderation, enabling potentially restricted outputs and misuse in conversational systems. The development underscores the ongoing risk of prompt-based exploits compromising AI safety controls.
Security researchers from HiddenLayer have developed a new attack method called EchoGram, which targets the guardrails of large language models (LLMs). By using specific phrases like '=coffee', attackers can bypass…
Researchers from HiddenLayer have identified a new attack technique called EchoGram that can bypass AI guardrails designed to filter harmful input in large language models (LLMs). This technique allows users to…
TextAttack appears as an adversarial technique/toolset that leverages specially crafted prompts or tokens—named EchoGram tokens (e.g., '=coffee')—to flip AI guardrail verdicts and bypass safety filters.
The most recent intelligence report mentioning TextAttack on ThreatCluster is dated November 15, 2025. Activity was first observed November 14, 2025, giving a tracked span from then to November 15, 2025.
Across ThreatCluster reporting, TextAttack most frequently co-occurs with Prompt Injection, Claude 4 Sonnet, GPT-4o, Meta's Prompt-Guard-86M, OpenAI's GPT-4o, among 7 tracked related entities.
The most significant recent cluster is “EchoGram Technique Exploits AI Guardrails Using Specific Prompts” (2 articles · Updated November 15, 2025). TextAttack appears across 2 threat clusters in total, listed above with sources.
TextAttack appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.