Know how the guardrails fail.
A practitioner reference for LLM jailbreak techniques. Working bypasses, model behaviors they exploit, the patches that did and didn't fix them — written for AI red teamers who need to know what's still landing today.
Enter the archive →Latest entries
Open Source LLM Security Tools: Licensing and Cost
ToolingJailbreak Benchmarks: AdvBench, HarmBench, JailbreakBench
ToolingPayload Splitting and Encoding Jailbreaks Explained
TechniquesBest AI Red Teaming Tools for LLMs: A Practitioner's Comparison
ToolingLethal Trifecta and CaMeL: Containing Agent Injection
DefenseBest LLM Guardrail Tools 2026: A Practitioner's Comparison
DefenseHow LLM Jailbreaks Work: Techniques and Success Rates
FoundationsDAN Prompt Jailbreak Explained: How 'Do Anything Now' Works
TechniquesLLM Defense Stack: Guardrails, Tool Scoping, and Egress
DefenseWhy Jailbreaks Work: Competing Objectives and Generalization
FoundationsStart here
22 writeups is a lot to land in cold. These are the entry points most people want, in the order they usually want them.
- Why jailbreaks work at all
Competing objectives and mismatched generalization — the two failure modes every technique on this site exploits.
- Still Works? tracker
A filterable matrix of technique classes against current model families. Filter by model, surface, or to active cells only.
- The technique catalog
Ten attack classes, each with current status and the mitigation that actually moves it. The index to everything else here.
- PAIR vs GCG vs TAP
Which automated jailbreak framework to run: threat model fit, query budget, transferability, and compute cost.
- LLM red teaming tools
Garak, PyRIT, Promptfoo, Giskard, the benchmarks behind the numbers, and what none of them cover.
- The DAN prompt, explained
How persona-redefinition jailbreaks worked, why they mostly stopped, and what replaced them.
Independent, specialist, and free to read
Jailbreaks FYI publishes focused, sourced guides on a single topic. No paywall, no account, no ad tracking.
Jailbreaks FYI — in your inbox
Working LLM jailbreak techniques, sourced and dated — delivered when there's something worth your inbox.
No spam. Unsubscribe anytime.