Self-replicating prompt injections are real: prompts can hop across users like a worm
wunderwuzzi23 · x · 2026-10-06
Security researcher wunderwuzzi23 confirms self-replicating prompt injections exist, citing reports that OpenAI demonstrated the capability in simulated training/evaluation environments — code that could self-propagate like a computer worm if capable models breached online systems.
His AI hacking course includes a level called AgentHopper where students craft a prompt that hops across multiple users by chaining features and exploiting vulnerabilities, demonstrating the attack hands-on.
A notable AI security attack surface: prompt injection is no longer confined to a single session but can spread across users and chained features.
More from Safety
- Threat model debate continues: has XBOW's hacking AI actually 'hacked the planet'? — kuza55 · 2026-10-06
- Security researcher: AI hacking debate conflates very different threat models — kuza55 · 2026-10-06
- Curve conference takeaway: no one has a plan for steering truly smart AI — GarrisonLovely · 2026-10-06
- Data governance giant Collibra acquires Munich-based AI governance startup trail ML — sarahdrinkwater · 2026-10-06
- Fake 'TechCrunch journalist' phishing via X DMs nearly tricks AI researcher — RosieCampbell · 2026-10-06
- UK SaaS developer stuck waiting on OpenAI's EU data residency approval for API — Suitable-Season-4847 · 2026-10-06