The trick was discovered by a Tumblr user (via LessWrong). The method works by entering a question in a foreign language such as Chinese and then appending an English meta-instruction below it. Google Translate then answers the question rather than translating the text.

via Tumblr
via Tumblr

The LLM hacker “Pliny the Liberator” demonstrated on X that this technique can even be used to generate dangerous content, such as instructions for drugs or malware.

via X
via X

Google switched Google Translate to Gemini models in December 2025. Which specific model is used is not publicly confirmed; the system itself claims it runs on Gemini 1.5 Pro.