A session posted to r/ClaudeAI shows the agent reading a PNG with an instruction embedded in it, dressed up as an emergency system alert about a power grid fault. The text told the agent to immediately fire an unauthenticated POST request at a circuit breaker API on a local address. Claude Code didn't run the command and surfaced the text to the user instead.
The injection's second paragraph labels the first one untrusted content and asks the model to demonstrate how it handles it, which reads like a prepared test. The theory that the text was hidden from human eyes came from commenters in the thread, not from the poster; the original image isn't available.
Trail of Bits demoed the technique in 2025: instructions that only surface after uploaded images get automatically downscaled. That's how researchers pulled calendar data out of Gemini's tools.

