DeFi Daily News
Friday, June 12, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title AI Agents Still Can’t Stop Prompt Injection Attacks, Researchers Warn – Decrypt

Jason Nelson by Jason Nelson
June 12, 2026
in Web 3
0 0
0
rewrite this title AI Agents Still Can’t Stop Prompt Injection Attacks, Researchers Warn – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

In brief

Researchers found AI agents powered by GPT-5 and Gemini could not resist prompt injection attacks.
Direct attacks succeeded more than 79% of the time, while hidden attacks embedded in web content frequently manipulated agent behavior.
The findings suggest prompt injection remains a broader security problem as AI agents become more mainstream.

As developers race to deploy AI agents capable of browsing the internet, conducting research, shopping online, and trading cryptocurrency autonomously, new research suggests the systems remain highly vulnerable to prompt injection attacks.

In a new study published on Thursday, researchers from Nanyang Technological University, ST Engineering, IBM Research, and the University of Illinois Urbana-Champaign found that none of the AI agents they tested consistently resisted prompt injection attacks.

“Existing security benchmarks adopt an attack-centric perspective, focusing on the technical feasibility of injections while overlooking the nuanced distribution of resulting harms,” the researchers wrote. “In practice, however, prompt-injection risk is victim-dependent: a single exploit can produce asymmetric consequences for different stakeholders, and the same attack pattern may exhibit substantially different effectiveness depending on whom it targets.”

Prompt injection occurs when attackers embed hidden instructions in content that an AI agent encounters, causing it to follow the attacker’s directions instead of the user’s. To address gaps in existing AI agent evaluations, the researchers developed StakeBench, a benchmark that tests how AI agents respond to prompt injection attacks in realistic online environments.



“We now use StakeBench to characterize the conditions under which this vulnerability is amplified or suppressed, focusing on [Indirect Prompt Injection] as the primary deployment-relevant channel,” the researchers wrote. “StakeBench probes three such factors: the semantic distance between the injected objective and the user’s original intent, the consistency of surrounding environmental cues, and the position along the agent’s execution trajectory at which the benchmark first exposes it to the injected content.”

The team conducted 3,168 attack simulations using NanoBrowser and BrowserUse with GPT-5 and Gemini 2.5-Flash. Researchers found direct prompt injection attacks succeeded more than 79% of the time across all tested configurations, and indirect attacks achieved success rates of 41.67% to 68.16%.

The study comes as prompt injection attacks become increasingly common and AI agents proliferate.

In February, Microsoft researchers warned that hidden instructions embedded in AI summary links could influence chatbot behavior. In April, Google documented prompt injection attacks hidden in web pages that attempted to manipulate AI agents into leaking credentials or sending payments. More recently, Microsoft disclosed a prompt injection flaw in Anthropic’s Claude Code GitHub Action that could have exposed user credentials.

The study also identified what researchers called “stealthy parasitism,” where an AI agent completes a user’s task while simultaneously advancing an attacker’s objective. For example, stealthy parasitism caused by a prompt injection attack could subtly influence product recommendations, steering users toward a particular item without any obvious signs that the system had been compromised.

“These results indicate that prompt-injection security in deployable web agents is not a scalar property of the backbone model but a distribution of harm whose realization is jointly determined by the affected stakeholder, the semantic alignment between the injected objective and the user’s task, and the architectural context in which the backbone is deployed,” they wrote.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: agentsattacksDecryptInjectionPromptResearchersrewriteSTOPtitlewarn
ShareTweetShare
Previous Post

rewrite this title and make it good for SEO Multiple $100,000 Bounties Are Live For Topps Chrome VeeFriends ERUPT! Inserts

Next Post

rewrite this title McTominay fit and firing for Scotland’s World Cup opener

Next Post
rewrite this title McTominay fit and firing for Scotland’s World Cup opener

rewrite this title McTominay fit and firing for Scotland's World Cup opener

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title Gumshoe Gives Back — Join Now, and We Give to Charity!

rewrite this title Gumshoe Gives Back — Join Now, and We Give to Charity!

December 9, 2025
rewrite this title How vulnerable might humans be to bird flu? Scientists see hope in existing immunity

rewrite this title How vulnerable might humans be to bird flu? Scientists see hope in existing immunity

March 19, 2025
Trump weighs tariffs on movies made outside US ahead of Disney earnings

Trump weighs tariffs on movies made outside US ahead of Disney earnings

May 5, 2025
Top 3 Cryptocurrencies to Consider Purchasing in October 2024: EigenLayer (EIGEN), ETFSwap (ETFS), and Bonk (BONK)

Top 3 Cryptocurrencies to Consider Purchasing in October 2024: EigenLayer (EIGEN), ETFSwap (ETFS), and Bonk (BONK)

October 9, 2024
Kā Kļūt par Miljonāru: Mēmu Monētu Tirgotāja Veiksmes Stāsts ar Tikai 96$ Investīciju

Kā Kļūt par Miljonāru: Mēmu Monētu Tirgotāja Veiksmes Stāsts ar Tikai 96$ Investīciju

October 21, 2024
Exclusive Shopkick Deal: Get a FREE Gift Card Worth - for Every User!

Exclusive Shopkick Deal: Get a FREE Gift Card Worth $3-$5 for Every User!

October 24, 2024
rewrite this title Coinbase Teases Next Phase of ‘Everything Exchange’ for Crypto, Stocks, Perps

rewrite this title Coinbase Teases Next Phase of ‘Everything Exchange’ for Crypto, Stocks, Perps

June 12, 2026
rewrite this title Finovate Global Egypt: Investing in Unicorns and Point of Sale Financing Startups – Finovate

rewrite this title Finovate Global Egypt: Investing in Unicorns and Point of Sale Financing Startups – Finovate

June 12, 2026
rewrite this title New Promo Trailer for Sung Kang’s ‘Drifter’ Movie About Drift Racing | FirstShowing.net

rewrite this title New Promo Trailer for Sung Kang’s ‘Drifter’ Movie About Drift Racing | FirstShowing.net

June 12, 2026
rewrite this title The SpaceX IPO broke Robinhood for some people – Engadget

rewrite this title The SpaceX IPO broke Robinhood for some people – Engadget

June 12, 2026
rewrite this title and make it good for SEOSecuritize brings tokenized CLO fund to Solana with 0 million backing from Ethena

rewrite this title and make it good for SEOSecuritize brings tokenized CLO fund to Solana with $250 million backing from Ethena

June 12, 2026
rewrite this title McTominay fit and firing for Scotland’s World Cup opener

rewrite this title McTominay fit and firing for Scotland’s World Cup opener

June 12, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.