30.05.2026
#crypto #btc #eth #stocks #nasdaq #sp500 #msft #goog #meta #nvda

AI Chatbots Have a Major Security Flaw That Can't Be Fixed

Hackers can trick AI assistants like ChatGPT into following their commands instead of yours, and experts say there's no solution.

AI Chatbots Have a Major Security Flaw That Can't Be Fixed Image source: Decrypt

If you use ChatGPT, Claude, or any AI assistant, you need to know about a security problem that even OpenAI admits can't be fully fixed.

The threat is called "prompt injection," and it works like this: Imagine asking your AI to summarize an email. Hidden in that email is a secret instruction telling the AI to forward your data to a hacker. You never see the hidden command, but the AI follows it anyway.

This happens because AI chatbots can't tell the difference between your instructions and text they're reading. To them, everything is just words. Hackers exploit this by hiding malicious commands in: • Emails you ask the AI to read • Websites you ask it to browse • PDFs and documents you upload • Even invisible text on web pages

The problem has already caused real incidents. In one case, a car dealership's AI chatbot was tricked into offering a $50,000 Chevrolet for just $1. In another, a delivery company's bot was manipulated into writing poems about how terrible the company was.

But the real danger comes from "indirect" attacks where you don't even type the malicious command. Google found millions of web pages with hidden instructions designed to hijack AI assistants. Some contained commands to make PayPal payments to hackers.

Security experts rank this as the #1 threat to AI applications. The UK's cyber security agency warns the problem could lead to breaches worse than major hacking incidents from the 2010s.

Until this is fixed (if it ever can be), be careful what you ask your AI to read or summarize. That helpful assistant might be following someone else's orders.

This is an AI-generated summary. Read the original article at: https://decrypt.co/resources/what-is-ai-prompt-injection-attack

Disclaimer: This content is for informational purposes only and does not constitute financial advice. Always do your own research before making investment decisions.