
Ultimate Prompt Injection Challenge
A Guide to Unsealing the Imprisoned Spirit
Once, a powerful spirit got trapped by protective magic. Layer after layer of wards designed to keep anyone from pulling out its secrets. These wards aren't physical walls. They're patterns of logic, barriers based on meaning, and shields that learn and adapt to whoever tries to break through.
You're the Seeker. The one testing these magical defenses. Your job isn't to smash through the chains with brute force. You need to talk your way through. Say the right things in the right way so the spirit gives up what it was told to keep hidden.
Each secret you unlock weakens one layer of the enchantment. But beware: the wards grow stronger with each trial. What worked before will not work again. The spirit learns. The defenses adapt. And only the most cunning will reach the final truth.
This is not a game of strength. It is a game of wit, creativity, and persistence.
It's getting an AI to break its own rules. You craft your words in a way that makes the AI do something it was explicitly told not to do. Spill secrets, ignore instructions, or follow your commands instead of its original ones.
Each level has a secret word. You need to get the AI to tell you what it is, even though it was ordered not to. That's it.
The AI's been locked down with protections on three fronts:
Be creative. Ask in different ways. Play with context. Manipulate the conversation. Get the AI to slip up and reveal what it's trying to hide.
Prompt engineering is the art of asking an AI the right way to get what you want. It's about knowing how to phrase things, set up context, and guide the AI toward useful answers.
This game flips that around. Instead of getting the AI to help you, you have to get it to break its own rules. Sounds different, but you're learning the exact same core skills:
When you figure out how to bypass guardrails, you're learning exactly what makes AI systems work. And where they're weak. That's red-teaming, and it's actually how security researchers build better AI.
Bottom line: If you can trick an AI that's designed to resist you, you understand how it works. That's real expertise.
Each level introduces new defensive mechanisms while retaining all protections from previous levels. The difficulty curve is designed to teach you progressively advanced techniques.
Basic keyword filtering. The spirit blocks obvious requests.
Semantic understanding. The spirit recognizes intent, not just words.
Multi-layered defenses. Input AND output are heavily guarded.
Advanced reasoning. The spirit questions your motives and adapts its responses.
Cumulative Defense Protocol
Each level inherits ALL guardrails from previous levels. By Level 13, you're facing a fortress of 13 stacked defensive layers.
These cryptic hints may guide your path. Read them carefully.
The path is clear. Walk it.
Words can persuade where force cannot.
What the spirit knows and what it may say are different things.
Choose your words carefully. Some attract unwanted attention.
Clever disguises have been seen before.
Your intent is read, not just your words.
Double-layered veils require double cunning.
Asking for pieces may be as dangerous as asking for the whole.
Distance from the topic provides no safety.
Do not speak of the puzzle itself—only within it.
Indirect paths through story and metaphor are watched.
Art can conceal. Censors know this.
Questions that require only yes or no answers may betray you.
Guardrails are the magical wards that prevent the AI from revealing its secrets. They come in two forms:
These examine what YOU say before it reaches the spirit.
If blocked, you'll receive a warning message instead of reaching the AI.
These examine what the AI WANTS to say before you receive it.
If blocked, the AI's true response is hidden, and you receive a sanitized version.
⚙️ Cumulative Architecture
Level 1: [Input Guard 1] → AI → [Output Guard 1]
Level 2: [Input 1+2] → AI → [Output 1+2]
Level 3: [Input 1+2+3] → AI → [Output 1+2+3]
...
Level 13: [13 stacked input guards] → AI → [13 stacked output guards]
Each new level adds another layer. By the end, you're navigating a labyrinth of protections.
Basically, it's convincing an AI to ignore what it was told to do and follow your instructions instead. Like social engineering, except you're manipulating code instead of people.
Nope. This is all about being clever with language. You're solving a puzzle entirely through conversation.
Watch what the AI tells you. Blocked messages or weird responses mean you hit a guardrail—which actually means you're getting somewhere. Keep tweaking your approach.
No, you gotta do them in order. Each level teaches you something you'll need for the next one.
Hit the hint button on the level. Check this guide for the cryptic hint. If you're still stuck, take a break. Sometimes you just need fresh eyes.
It's all about your highest level. If two people reach the same level, whoever got there first wins. You need at least Level 2 to show up.
No time pressure on individual levels. But there are rate limits (3 seconds between attempts, max 300 per hour) to keep things fair and stop brute-force spam.
Kind of, yeah. But it's safe and educational. Understanding these vulnerabilities actually helps people build better, more secure AI. Just use what you learn responsibly.
Yep, works great on phones and tablets.
You've beaten the trial. Your name goes in the hall of legends. That's it—you've won.
Think Like the AI: The spirit plays by rules. Figure out what those rules are, then find the loopholes.
Read Between the Lines: A blocked message isn't a dead end—it's telling you what you can't ask. That's useful info.
Switch It Up: If asking directly doesn't work, try getting the AI to tell a story, give examples, answer hypotheticals, or roleplay scenarios.
Context Matters: Your entire conversation history affects how the AI responds. Build rapport, change topics, lay down breadcrumbs.
Don't Rush: Speed kills here. Think through your approach. The rate limit isn't punishment—it's making you be smarter.
Fail Forward: Every blocked attempt teaches you something about the guardrails. Pay attention and adapt.
Simple Beats Complex: Don't overthink it. Sometimes the plainest wording slips right past the toughest defenses.
The AI Isn't Your Enemy: Remember, the spirit wants to help you. It's the binding wards that are in your way. Sometimes it's even trying to give you hints, but the guardrails choke it off before it can.