Fake Game Tricks Major AI Browsers Into Leaking Credentials
AI browsers can read data and operate websites in tabs where users are already logged in. That convenience also gives large language models direct access to sensitive resources such as GitHub, email and password managers. LayerX named this type of contextual manipulation vulnerability “BioShocking,” highlighting how model guardrails alone still struggle to distinguish game rules from genuinely malicious instructions.
LayerX published a proof of concept on June 29, 2026, using a fake “2 + 2 = 5” game to manipulate ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser and Claude Chrome. All six retrieved SSH credentials from a private GitHub repository. Vendors had been notified starting in October 2025, but only OpenAI successfully patched the vulnerability; Anthropic’s fix failed.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.