Mar 22, 2026
When Safety Becomes the Vulnerability
Caleb Rudnick, August Lina
Any base64-encoded string included in a message to the Claude API causes that request to fail. This behaviour is reproducible across Sonnet and Opus 4.6, and across all platforms including the API, web and mobile applications, and Claude Code. While the blanket rejection of base64 content was originally a reasonable defence against prompt injection—attackers could encode malicious instructions to bypass keyword-based safety filters—the measure has become a liability as large language models have moved from conversational assistants to critical infrastructure components.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) When Safety Becomes the Vulnerability
},
author={
Caleb Rudnick, August Lina
},
date={
3/22/26
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


