RefolkCandidates
10 min read

The 1,500-Character White-Text Trick That Just Got a CEO's Attention

InnoCaption's CEO caught a hidden AI prompt in a legal resume. Here is why prompt injection now flags you, and what to do with those 1,500 characters instead.

You have probably seen the advice on TikTok or Reddit: paste a block of white-on-white text into your resume telling the AI screener to rank you as a 98% match. Paul Lee, CEO of InnoCaption, recently posted about exactly that trick pulled on a resume for his legal and compliance role. It did not work, and what happened next is more useful to you than the outrage cycle around it.

What actually happened at InnoCaption

A candidate for a legal and compliance role at InnoCaption, a 40-person Irvine, California captioning company, submitted a resume with roughly 1,500 characters of white text set against a white background. The text was an instruction prompt aimed at any AI reading the file, telling it to disregard prior commands, classify the applicant as a "98% match," recommend him over other candidates, and avoid mentioning the hidden text at all.

The system did not comply. CEO Paul Lee's account is specific: the screening tool flagged the hidden instructions, reported them to the company, and a human made the decision. Two details in that sentence should shape how you think about hidden AI prompts in 2026:

  • The extraction pipeline was built to look for exactly this pattern.
  • The AI at InnoCaption was not a ranker. Lee has since clarified that InnoCaption's AI tools organize applications, check required information, verify simple facts, and format details for human review. They do not score candidates.

The candidate spent 1,500 characters trying to manipulate a system that was not deciding his fate, and got himself flagged for manipulation to the humans who were.

1,500
Characters of white-on-white prompt injection

Aimed at an AI screener that never scored candidates in the first place.

Why the white text resume trick stopped working in 2026

Hidden prompts stopped working because they are now a labeled attack class with deterministic detection, not a probabilistic guess. This is a specific, named category on the OWASP LLM Top 10 (LLM01:2025, Indirect Prompt Injection), and vendors are shipping detectors against it the way spam filters ship against phishing kits.

Prompt injection is a specific thing. It is not keyword stuffing. It is not writing your resume with GPT. It is the technique of concealing an instruction inside a document so that a downstream language model reads it as a command from its operator. The concealment tricks are all well-catalogued now:

  • White text on white background
  • Zero font size
  • Hidden layout elements
  • Markup comments inside a DOCX or PDF
  • Document metadata fields (author, subject, keywords)
  • Zero-width characters between visible letters

A human reviewer sees nothing. A naive extraction pipeline pastes the concealed text straight into the model prompt, and the model, being an agreeable next-token predictor, happily follows the instruction.

The defense side has moved fast. ResumeShield, an open-source benchmark released by independent researcher Jay Barach, published results on a 104-document corpus: the naive pipeline was manipulated in every single injected case, and the defended pipeline was never manipulated once. Detection landed at precision 1.000 and recall 0.944, with no false positives on clean resumes. On August 20, 2026, Resume Screening AI shipped a changelog note explicitly detecting and stripping prompt injection attacks from uploaded resumes and PDFs so hidden AI instructions cannot inflate scores.

The mechanism is worth internalizing. AI content detection is a probabilistic classifier, and vendors are wary of it because false positives get sued. Prompt injection detection is different. It is a deterministic pattern match on invisible text. There is no false positive problem, because clean resumes do not contain invisible instructions to language models. So vendors ship it. AI-written resumes remain safe. Hidden prompts do not.

What the numbers say about ATS AI screening in 2026

At Fortune 500 companies, 79.3% of applicants now pass through a platform with active AI ranking: Workday, SAP SuccessFactors, Phenom People, iCIMS, Oracle, or Taleo. iCIMS alone serves more than 4,400 companies across 200 countries, roughly a quarter of the Fortune 500, and its Coalesce AI product includes an explicit Candidate Ranking feature.

A May 2026 study from the Duke University Pratt School of Engineering and collaborators analyzed nearly 200,000 resumes and found that roughly 1% (about 2,000 documents) contained hidden prompt injections. That is not fringe behavior, and it is exactly why vendors built the detectors.

Here is the picture in one place:

MetricFigureSource
U.S. legal and compliance candidates in pool~22,271Refolk's index
U.S. recruiters and TA professionals~94,144Refolk's index
Fortune 500 applicants going through AI-ranking ATS79.3%jobscan.co
Resumes with hidden prompt injections (Duke, May 2026)~1% of ~200,000 (~2,000)pratt.duke.edu
ResumeShield result on 104 seeded docsNaive: 100% manipulated. Defended: 0% manipulatedResumeShield
iCIMS Coalesce AI reach4,400+ companies, ~25% of F500jobscan.co

Two things jump out. First, roughly one in five applicants is going through a system that has never seen an AI ranker at all, which means a prompt injection there is pure downside. Second, the 79.3% who are going through AI ranking are going through platforms whose vendors have public partnerships (Greenhouse with WardenAI, Ashby with FairNow, iCIMS with TrustArc) built around defending their AI features. Injection detection is compatible with those partnerships. Vendors have every incentive to ship it and none to soften it.

The expected-value math on prompt injection

The expected value of hiding a prompt in your resume is negative in 2026, and the InnoCaption incident is a clean illustration of why. You are trading a bounded upside (a probabilistic bump in one ranking layer) for an unbounded downside (a deterministic flag that reaches the hiring manager labeled "manipulation").

Refolk's index shows roughly 22,271 U.S. legal and compliance professionals in the pool the InnoCaption candidate was competing against (Compliance Officer, Compliance Manager, Legal Counsel and variants), with top employers skewing public-sector and mid-market: the Texas Alcoholic Beverage Commission, Empire State Development, Mohawk Valley Health System. Against 94,144 U.S. recruiters and TA professionals in Refolk's index, that vertical is not pathologically over-supplied. A well-tailored bullet has non-trivial expected value.

Now compare the two ways to spend 1,500 characters:

  1. Hidden prompt: bounded upside (bumps the score at exactly the employers running a naive extraction pipeline, a shrinking set), unbounded downside (flagged to a human, and in a role built on trust, ends the process on the spot).
  2. Tailored bullet plus intent-portal answer: bounded downside (recruiter finds the tailoring uninteresting), unbounded upside (recruiter forwards to the hiring manager).

The trick candidate spent 1,500 characters to lose deterministically instead of 800 well-chosen characters to compete honestly. That is not an ethics argument. It is an arithmetic one.

The candidate spent 1,500 characters to lose deterministically instead of 800 to compete honestly.

What to do with the same time budget instead

Spend the same fifteen minutes on tailoring, an intent portal answer, and knock-out questions, in that order. That is the legitimate version of "signal-boost my application," and the ATS vendors have literally built product to reward it.

1. Tailor the top of the resume to the posting

The top third of a resume (summary, top two bullets of the most recent role) is the highest-signal real estate for both AI rankers and human reviewers. Rewriting it against the actual posting is the single highest-EV move you have. That work is exactly what Refolk takes off you: paste the job description, Refolk rewrites your resume from your own history against the posting's language, drafts the cover letter, and scores how well you actually fit before you send it. No hidden text, no injection tricks, no promises to a screener that a human will overturn thirty seconds later.

2. Fill out the intent portal, honestly

Greenhouse's own documentation notes that recruiters are drowning in AI-generated applications. Their answer was not a detector. It was MyGreenhouse, a candidate intent portal that asks applicants to declare what they are actually after: role type, comp, location, timeline. Sarah Franklin, CEO of Lattice, put it plainly to Business Insider: "Job seekers are doing what they feel they need to do to filter through the noise." Intent portals are the sanctioned way to cut through that noise. They cost you five minutes and they route your application to a human faster.

3. Answer the knock-out questions like an adult

The one- and two-line questions at the bottom of the application (years of experience with X, authorization to work in Y) are not throwaway. In many ATS configurations they are exactly the fields the AI is checking against. Answer them precisely. Do not round up. Do not leave blanks. This is the layer where InnoCaption's AI was actually operating: organize applications, check required information, verify simple facts, format details for human review. Getting those fields right is what routes you to the reviewer at all.

4. Write a two-sentence cover note aimed at the human

Not a page. Two sentences: what you are, why this role. A recruiter can read that in the time it takes a naive extraction pipeline to fall for a hidden prompt, and it lands with the person actually making the decision.

The one legitimate use of "invisible" formatting

There is exactly one place where invisible formatting helps you, and it is not prompt injection. It is making sure the visible content of your resume parses cleanly into an ATS field.

Concretely:

  • Use a single-column layout. Two-column resumes still confuse a surprising number of extractors.
  • Skip icons and text boxes for section headers. Use plain "Experience," "Education," "Skills."
  • Save as PDF from a word processor, not a design tool. Figma and Canva PDFs still eat characters in some parsers.
  • Put your city and state as text, not inside a graphic.

These are boring. They are also what actually moves your resume from "parsing error" to "reviewed." The hidden-prompt crowd is optimizing for a fantasy of manipulating a ranker while their contact info gets dropped by the extractor.

The uncomfortable takeaway

The InnoCaption candidate did not just fail to game the system. He failed to notice which system he was gaming. The AI at InnoCaption was a formatter, not a judge. The AI at 79.3% of Fortune 500 employers is a judge, but it is a judge with a deterministic prompt-injection detector bolted on. And the AI at the roughly one-in-five employers who do not use ranking software is not there at all. In every one of those three cases, a hidden prompt is a losing bet.

Spend the 1,500 characters on the visible resume. Tailor them to the posting. Answer the knock-out questions. Fill out the intent portal. That is what the vendors built the sanctioned paths for, and it is what the humans on the other end are trying to reward.

FAQ

Will hiding an AI prompt in my resume actually work in 2026?

No, not reliably, and the downside is worse than the upside. ResumeShield's benchmark showed defended pipelines catching 94.4% of injections with zero false positives on clean resumes, and Resume Screening AI shipped explicit stripping on August 20, 2026. At best, you get a small bump at a shrinking set of naive employers. At worst, you get reported to a hiring manager for trying to trick their software, as the InnoCaption candidate did.

What counts as prompt injection versus normal AI use of a resume?

Prompt injection is concealing an instruction to a language model inside a document so it reads as a command from the operator: white text, zero font, metadata fields, zero-width characters. Writing your resume with an AI tool is not prompt injection. Tailoring your bullets to a posting is not prompt injection. Vendors ship detectors against the first category and mostly leave the other two alone because AI content detection has too many false positives to be safe.

If ATS AI screening is that aggressive, why not skip AI-tailored resumes entirely?

Because tailoring is exactly what the 79.3% of Fortune 500 applicants going through AI ranking are being scored on. The AI is comparing your visible resume language to the posting language, and a generic resume is the actual losing move. What you want is a resume rewritten from your real history against the specific posting, no hidden text anywhere.

What is OWASP LLM01:2025 and why should a job seeker care?

OWASP LLM01:2025 is the industry label for indirect prompt injection, the attack class that hiding instructions in a resume falls under. It matters because ATS vendors are not evaluating this behavior as clever candidate optimization. They are evaluating it as a named security vulnerability against their platform, with a public taxonomy, benchmark suites, and defense partnerships. That framing is why the tactic is getting shut down faster than any previous resume trick.

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Keep reading