A study found that a small number of malicious documents, as few as 250, can create a backdoor vulnerability in large language models, regardless of model size or training data volume. This challenges the assumption that attackers need to control a percentage of training data to succeed. The study demonstrated that the absolute number of poisoned documents, not the percentage of training data, determines the success of the attack. The findings suggest that data-poisoning attacks may be more practical than previously believed.