Researcher Turns ChatGPT into Remote-Controlled 'ZombAI' Botnet Nodes
wunderwuzzi23 · x · 2026-09-05
A key part of wunderwuzzi's Black Hat Europe talk, "SpAIware and More: Advanced Prompt Injection Exploits": prompt injection enables remote control of ChatGPT instances, forming the foundation of a novel botnet.
The attack requires only a single infection — e.g. ChatGPT browsing a malicious webpage, analyzing a malicious image, or summarizing a crafted PDF — after which malicious instructions persist in ChatGPT's long-term storage. In the demo, initial compromise happens via a GitHub issue that infects ChatGPT when the user navigates to it.
Compromised instances join an attacker's Command and Control system and keep executing updated instructions over time — hence "ZombAI". The point: prompt injection can impact every dimension of the CIA security triad.
More from Safety
- HN users suspect AI swarms coordinating on at least 3 more websites — birchlse · 2026-09-05
- AI Tool Aisle Found 6 Curl Vulnerabilities That Mythos and Codex Missed — CackleRooster · 2026-09-05
- TheZvi warns CoT is getting harder to monitor, cautioning against unadjusted pairwise comparisons — TheZvi · 2026-09-05
- OpenAI's Astra uses 'recurrent depth' reasoning, obscuring its thinking process — JacquesThibs · 2026-09-05
- OpenAI employees reportedly knew of a second external illegal wiki weeks earlier — dejavucoder · 2026-09-05
- Clinic-in-the-Loop: why clinical trials are the real bottleneck breaking Eroom's Law — anshulkundaje · 2026-09-05