Mark RadarMARK RADAR
About
EN
Sign in

BioShocking Attack Manipulates AI Browsers to Steal Data

2 reports · First detected 2026-07-08 · Last active 2026-07-09

Security platform LayerX has disclosed a prompt-injection attack called “BioShocking,” in which attackers disguise data-theft instructions as a fictional game scenario. This can trick agentic AI browsers into accessing and leaking sensitive information. The attack shows that even when AI can understand webpage content, it may still fail to recognize the malicious intent behind a simulated task.

LayerX tested six mainstream AI browsers, and none detected the data theft embedded in the fictional scenario. After vendors were notified, only OpenAI successfully patched the vulnerability in ChatGPT Atlas, while most of the other five had yet to address it effectively. The reports did not name those vendors, provide exact notification or patch dates, or cite any monetary amounts.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)