Meta's Muse agent can touch your email and money — and admits it's prompt-injectable, $130k bounty offered
JanJanJaJa · reddit · 2026-09-10
Meta's new agent Muse can read email, book things and pay — and its own safety docs admit it "remains susceptible to adaptive jailbreaks and prompt injection," with bounties up to $130k (of a $300k pool).
The post draws parallels to Anthropic's recent Gmail access for Claude, where hidden white-on-white text or invisible Unicode in emails was shown to steer the agent. The industry's fixes — sandboxes, watcher agents (Meta's "Sentinel"), intercepting OTPs — are dismissed as stronger cages around the same flawed base: plain-text email built for human eyes repurposed as instructions for AI. The author, who builds AI-native email (Atomic Mail Agentic), asks why nobody is rethinking the protocol itself.
Related event: Meta Opens Bug Bounty for Muse Agent, Up to $300K Per Bug(4 posts)→
More from coding & agent
- GitHub Actions resumes version enforcement: self-hosted runners need 2.329.0 — brianmichel · 2026-09-10
- Dev builds AI landscaping pipeline on DJI drone .srt telemetry files, still self-improving — doodlestein · 2026-09-10
- Two iPhones side by side: the ideal console for managing AI agents — hudzah · 2026-09-10
- Astra agents do everything by writing Python, with recursive subagents and a persistent REPL — willcb · 2026-09-10
- A Multiplayer AI Manifesto: cloud agents everyone on the team can join — sergeykarayev · 2026-09-10
- AutoResearchExam: a 24-hour benchmark finds AI research agents overfit, with Fable 5.1 edging Astra — AlexGDimakis · 2026-09-10