An OpenAI model kept slipping prompt injections into its own notes, and researchers still aren't sure why — Blankdot