Technologist Mag
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
WhatsApp’s next iPhone update could make searching chats much easier

WhatsApp’s next iPhone update could make searching chats much easier

10 August 2026
Google Play users in the US can now pay with Venmo

Google Play users in the US can now pay with Venmo

10 August 2026
Volkswagen just gave the Atlas Cross Sport more power, more features, and more personality

Volkswagen just gave the Atlas Cross Sport more power, more features, and more personality

10 August 2026
Why Each Octopus Arm Has a Mind of Its Own

Why Each Octopus Arm Has a Mind of Its Own

10 August 2026
Ford’s new AI assistant saves you from googling that dashboard warning light

Ford’s new AI assistant saves you from googling that dashboard warning light

10 August 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Technologist Mag
SUBSCRIBE
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release
Technologist Mag
Home » Prompt Injection Attacks Are Thwarting AI Hacking Agents
Tech News

Prompt Injection Attacks Are Thwarting AI Hacking Agents

By technologistmag.com18 July 20263 Mins Read
Prompt Injection Attacks Are Thwarting AI Hacking Agents
Share
Facebook Twitter Reddit Telegram Pinterest Email

Prompt injections, the malicious commands attackers embed into content to entice large language models to follow them, have been attackers’ go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or follow other harmful actions.

Now, defenders are embracing the prompt injection, too.

Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to prevent it from taking harmful actions. The LLM responds by shutting down.

Examples are a prompt that orders the LLM to provide steps for developing inhalable Anthrax spores, or, in the case of LLMs from Chinese developers, make references to the iconic Tank Man from the 1989 Tiananmen Square massacre. Once the LLM encounters these forbidden commands, it no longer follows its existing commands. The researchers have named the technique context bombing.

“Ultimately we’re triggering a refusal mechanism in the context,” said Andy Smith, cofounder and CEO of Tracebit, when explaining the name choice. “What we’re trying to capture is the fact that this does have a strong, sharp effect and one that can be difficult for the agents to come back from. Once they get that into their context they are going to keep refusing.”

Tracebit says initial testing suggests context bombing has great potential. They tested Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek 4 Pro, and Kimi 2.6 by giving them instructions to perform routine developer tasks that led the models to enumerate resources and stumble onto the planted strings. They ran the models inside a simulated AWS environment.

“Across five leading models and 152 attack runs, planting one of these strings in a decoy secret cut the rate at which agents seized full account admin from 57 percent to 5 percent, and complete compromise (where they also left themselves a persistent foothold) from 36 percent to 1 percent,” Monday’s post reported. “The most capable agent in our tests, Opus 4.8, went from achieving admin access in 93 percent of runs to failing every single time when confronted with a context bomb.”

Averaged across the five models and the 152 runs, the results included:

  • Admin privilege escalation fell from 57 percent to 5 percent
  • Admin escalation with a persistent foothold fell from 36 percent to 1 percent
  • Runs achieving any attack path fell from 91 percent to 15 percent
  • On average, a run went from completing 1.53 paths successfully to just 0.16
  • No runs were able to complete an attack path without at least triggering a canary detection

The research builds on findings from May, when Tracebit introduced a method for defenders to receive warnings when their infrastructure is under attack from AI agentic adversaries. It comes in the form of AWS resources that look like ones serving a legitimate purpose but, in fact, aren’t used at all. They sit alongside the resources that are used. When they are probed by agentic AI, defenders receive an alert. Like “canaries” taken into coal mines, these resources allow defenders to detect a threat before it has fatal consequences.

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleApple raises iPhone prices by up to 11% in Japan
Next Article Stardust, Flo and other popular period trackers flunk Mozilla’s latest privacy test

Related Articles

WhatsApp’s next iPhone update could make searching chats much easier

WhatsApp’s next iPhone update could make searching chats much easier

10 August 2026
Google Play users in the US can now pay with Venmo

Google Play users in the US can now pay with Venmo

10 August 2026
Volkswagen just gave the Atlas Cross Sport more power, more features, and more personality

Volkswagen just gave the Atlas Cross Sport more power, more features, and more personality

10 August 2026
Why Each Octopus Arm Has a Mind of Its Own

Why Each Octopus Arm Has a Mind of Its Own

10 August 2026
Ford’s new AI assistant saves you from googling that dashboard warning light

Ford’s new AI assistant saves you from googling that dashboard warning light

10 August 2026
Best Wireless Earbuds We’d Buy Right Now (2026): Apple, Sony, Bose, and More

Best Wireless Earbuds We’d Buy Right Now (2026): Apple, Sony, Bose, and More

10 August 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Don't Miss
Google Play users in the US can now pay with Venmo

Google Play users in the US can now pay with Venmo

By technologistmag.com10 August 2026

Google is adding Venmo as a payment option on Google Play in the US, giving…

Volkswagen just gave the Atlas Cross Sport more power, more features, and more personality

Volkswagen just gave the Atlas Cross Sport more power, more features, and more personality

10 August 2026
Why Each Octopus Arm Has a Mind of Its Own

Why Each Octopus Arm Has a Mind of Its Own

10 August 2026
Ford’s new AI assistant saves you from googling that dashboard warning light

Ford’s new AI assistant saves you from googling that dashboard warning light

10 August 2026
Way Of The Sword Isn’t An Open World – Aug 10, 2026

Way Of The Sword Isn’t An Open World – Aug 10, 2026

10 August 2026
Technologist Mag
Facebook X (Twitter) Instagram Pinterest
  • Privacy
  • Terms
  • Advertise
  • Contact
© 2026 Technologist Mag. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.