If this were true, the attacker would need to send prompts to retrieve information, making it an easy attack for the user to spot. However, if the malicious actor has the power to delete prompts and chats, I would suspect they already have access to every other chat.
I doubt he was singing for itself, most probably it wasn’t singing for us.