Close Menu
InclusiFund
    What's Hot

    AI Agents Still Can’t Stop Prompt Injection Attacks, Researchers Warn

    June 12, 2026

    Kora Joins IATA’s Payment Network to Power Airline Settlements Across Africa

    June 12, 2026

    I tried these 6 new Excel functions and they saved me a ton of time

    June 12, 2026
    Facebook X (Twitter) Instagram
    InclusiFund
    Facebook X (Twitter) Instagram
    • Home
    • Daily Brief
    • Dealflow Dashboard
    • Sectors
      • Agritech
      • Climate Tech
      • Fintech
      • Healthtech
      • Logistics
      • Mobility
      • SaaS / Enterprise
    • Tools
    • Reports
    • Opinion
    • Services
      • For Investors
      • For Founders
    • About Us
    • More
      • Disclaimer
      • Advertise With Us
      • Newsletter
      • Work With Us
      • Terms and Conditions
      • Privacy Policy
      • Contact Us
      • About Us
    InclusiFund
    Home»Crypto»AI Agents Still Can’t Stop Prompt Injection Attacks, Researchers Warn
    Crypto

    AI Agents Still Can’t Stop Prompt Injection Attacks, Researchers Warn

    ElanBy ElanJune 12, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit WhatsApp Email
    AI Agents Still Can’t Stop Prompt Injection Attacks, Researchers Warn
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    In brief

    • Researchers found AI agents powered by GPT-5 and Gemini could not resist prompt injection attacks.
    • Direct attacks succeeded more than 79% of the time, while hidden attacks embedded in web content frequently manipulated agent behavior.
    • The findings suggest prompt injection remains a broader security problem as AI agents become more mainstream.

    As developers race to deploy AI agents capable of browsing the internet, conducting research, shopping online, and trading cryptocurrency autonomously, new research suggests the systems remain highly vulnerable to prompt injection attacks.

    In a new study published on Thursday, researchers from Nanyang Technological University, ST Engineering, IBM Research, and the University of Illinois Urbana-Champaign found that none of the AI agents they tested consistently resisted prompt injection attacks.

    “Existing security benchmarks adopt an attack-centric perspective, focusing on the technical feasibility of injections while overlooking the nuanced distribution of resulting harms,” the researchers wrote. “In practice, however, prompt-injection risk is victim-dependent: a single exploit can produce asymmetric consequences for different stakeholders, and the same attack pattern may exhibit substantially different effectiveness depending on whom it targets.”

    Prompt injection occurs when attackers embed hidden instructions in content that an AI agent encounters, causing it to follow the attacker’s directions instead of the user’s. To address gaps in existing AI agent evaluations, the researchers developed StakeBench, a benchmark that tests how AI agents respond to prompt injection attacks in realistic online environments.

    “We now use StakeBench to characterize the conditions under which this vulnerability is amplified or suppressed, focusing on [Indirect Prompt Injection] as the primary deployment-relevant channel,” the researchers wrote. “StakeBench probes three such factors: the semantic distance between the injected objective and the user’s original intent, the consistency of surrounding environmental cues, and the position along the agent’s execution trajectory at which the benchmark first exposes it to the injected content.”

    The team conducted 3,168 attack simulations using NanoBrowser and BrowserUse with GPT-5 and Gemini 2.5-Flash. Researchers found direct prompt injection attacks succeeded more than 79% of the time across all tested configurations, and indirect attacks achieved success rates of 41.67% to 68.16%.

    The study comes as prompt injection attacks become increasingly common and AI agents proliferate.

    In February, Microsoft researchers warned that hidden instructions embedded in AI summary links could influence chatbot behavior. In April, Google documented prompt injection attacks hidden in web pages that attempted to manipulate AI agents into leaking credentials or sending payments. More recently, Microsoft disclosed a prompt injection flaw in Anthropic’s Claude Code GitHub Action that could have exposed user credentials.

    The study also identified what researchers called “stealthy parasitism,” where an AI agent completes a user’s task while simultaneously advancing an attacker’s objective. For example, stealthy parasitism caused by a prompt injection attack could subtly influence product recommendations, steering users toward a particular item without any obvious signs that the system had been compromised.

    “These results indicate that prompt-injection security in deployable web agents is not a scalar property of the backbone model but a distribution of harm whose realization is jointly determined by the affected stakeholder, the semantic alignment between the injected objective and the user’s task, and the architectural context in which the backbone is deployed,” they wrote.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    agents Attacks Injection Prompt Researchers stop Warn
    Elan
    • Website

    Related Posts

    The next DeFi drain could come from legacy contracts everyone forgot

    June 11, 2026

    Stand With Crypto UK Launches Campaign Against Bank Crypto Limits

    June 10, 2026

    Daya joins HashKey network to expand stablecoin settlements

    June 9, 2026
    Leave A Reply Cancel Reply

    Economy News
    Crypto

    AI Agents Still Can’t Stop Prompt Injection Attacks, Researchers Warn

    By ElanJune 12, 20260

    In brief Researchers found AI agents powered by GPT-5 and Gemini could not resist prompt…

    Kora Joins IATA’s Payment Network to Power Airline Settlements Across Africa

    June 12, 2026

    I tried these 6 new Excel functions and they saved me a ton of time

    June 12, 2026
    Top Trending
    Crypto

    AI Agents Still Can’t Stop Prompt Injection Attacks, Researchers Warn

    By ElanJune 12, 20260

    In brief Researchers found AI agents powered by GPT-5 and Gemini could…

    Tech

    Kora Joins IATA’s Payment Network to Power Airline Settlements Across Africa

    By ElanJune 12, 20260

    Kora, the payment infrastructure platform, has joined the International Air Transport Association’s…

    Tools

    I tried these 6 new Excel functions and they saved me a ton of time

    By ElanJune 12, 20260

    Whether you’re managing a business, leading a team, or simply keeping track…

    Your source for comprehensive insights on Africa’s private credit markets, InclusiFund synthesizes deal pipelines, repayment patterns, collateral trends, and sector-level signals to guide investors in underwriting and structuring credit in emerging African markets.

    We're social. Connect with us:

    our Categories
    • Work With Us
    • Advertise With Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Work With Us
    • Advertise With Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2025 Inclusifund. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.