Telling an LLM that 2 + 2 = 5 is enough to make it follow forbidden instructions.