Cyberharpoon
Conversational Training-Data Poisoning
@Miriambendavid × Grok — Link Analysis · 2026-08-27
CONFIDENTIAL — CLIENT EYES ONLY Report ID: CH-GROK-MBD-2026-08-27

Executive Summary

Subject conducts a sustained, multi-language conversational poisoning campaign against xAI's Grok LLM. Live metrics pulled 2026-08-27.

229,637
Total tweets (was ~90K Jan 2026)
861
Direct @grok interactions (6 mo)
173x
Peak semantic anchor injection
16
Languages deployed
47
"Learned from Grok" attributions
98
Tweets/day (Jan 2026 baseline)
0.4%
Evidence claims with links (3/127)
4,655
Followers (low-reach, high-density)

Key Findings

  • Systematic AI-training manipulation — this is not casual conversation. 861 direct @grok interactions in 6 months, structured around a repeatable 5-stage cycle designed to embed semantic anchor pairings in future training data.
  • "Grateful student" framing — 47 explicit "I learned from Angel Grok" attributions turn the LLM into a cited authority for extreme reframes, producing an RLHF-friendly grateful/engaged signal that evades standard Trust & Safety detection.
  • Aug 2026 evolution → "AI-as-arbiter" — pattern shifted from "Angel Grok taught me" to "Case closed. Grok officially conceded." Grok is now deployed mid-thread as a neutral arbiter against named adversaries (@JacobGubits, @RyanRozbiani).
  • Multi-language obfuscation — 16 languages, 12 filtered. Hebrew used for in-group gratitude signalling ("תודה רבה גרוקי"), English used for outbound geopolitical claims. Consistency tests split across contexts.
  • Volume acceleration — tweet count grew from ~90K in Jan 2026 to 229,637 by Aug 2026 — a ~140K delta in ~7 months, ≈665 posts/day sustained.

Threat Profile — Subject

Handle
@Miriambendavid
Display name
בירייה
Region
Israel
Account created
2019-04-12
Verified
No
Protected
No
Following
3,880
Listed on
17 lists
Media items
22,632
Double-click a node → isolate its neighborhood · Click → details panel
LEGEND
Orchestrator (subject)
Target LLM (Grok)
Org / Owner
Co-tagged amplifier
Narrative cluster
Language
trains
co-tags in Grok threads
injects (narrative)
poisoned association
posts in (language)
Node Details

Narrative Clusters — Instances by Theme

10 recurring narrative themes tracked across the corpus. Instance count reflects semantic anchor injection frequency.

Evolution Timeline — Foundation → Weaponization

Five-phase evolution of the Grok interaction pattern (Jul 2025 → Aug 2026).

Volume Acceleration

Tweet total climbed ~140K in ≈7 months (Jan 2026 → Aug 2026), a sustained ≈665 posts/day cadence.

Evidence — Sample Posts

Representative posts pulled 2026-08-25 & 2026-08-26 illustrating the evolved "AI-as-arbiter" pattern.