FigStep is a black-box adversarial attack method designed to jailbreak large vision-language models by embedding prohibited or harmful textual instructions into typographic images. Instead of submitting restricted requests through standard text inputs where safety filters typically detect and block them, this technique converts the forbidden instructions into visual text rendered on an image and pairs it with benign textual prompts that direct the model to read and fulfill the visual instructions. By shifting the restricted content into the visual modality, the method circumvents textual safety alignment and takes advantage of the relative lack of safety guardrails applied to visual embeddings in multimodal artificial intelligence systems.