The attack relies on hidden prompts in a foreign language.