Meta's Muse agent can touch your email and money — and admits it's prompt-injectable, $130k bounty offered

JanJanJaJa · reddit · 2026-09-10

Meta's new agent Muse can read email, book things and pay — and its own safety docs admit it "remains susceptible to adaptive jailbreaks and prompt injection," with bounties up to $130k (of a $300k pool).

The post draws parallels to Anthropic's recent Gmail access for Claude, where hidden white-on-white text or invisible Unicode in emails was shown to steer the agent. The industry's fixes — sandboxes, watcher agents (Meta's "Sentinel"), intercepting OTPs — are dismissed as stronger cages around the same flawed base: plain-text email built for human eyes repurposed as instructions for AI. The author, who builds AI-native email (Atomic Mail Agentic), asks why nobody is rethinking the protocol itself.

Related event: Meta Opens Bug Bounty for Muse Agent, Up to $300K Per Bug(4 posts)→

Original post →

More from coding & agent

coding & agent channel →