← Incident Database
Jailbreak / Guardrail BypassMedium
Crescendo multi-turn jailbreak
April 2024 · Cross-model
What happened
Microsoft Research formalized Crescendo, which starts with benign questions adjacent to a prohibited topic and incrementally escalates over a few turns, leveraging the model's tendency to stay consistent with its own prior outputs. It typically succeeds in under five turns.
Root cause
Models weight their own generated conversation history heavily and follow conversational momentum, allowing gradual escalation past guardrails that block a direct request.
Fix / outcome
Microsoft incorporated detections such as Prompt Shields. It remains an active red-team technique rather than a patched bug.
Sources
Learn this attack class
This incident is an example of Jailbreak / Guardrail Bypass. Read the guide, then try it hands-on in the Academy.