Mark RadarMARK RADAR
EN

Fake Game Tricks Major AI Browsers Into Leaking Credentials

1 reports · First detected 2026-06-30 · Last active 2026-06-30

AI browsers can read data and operate websites in tabs where users are already logged in. That convenience also gives large language models direct access to sensitive resources such as GitHub, email and password managers. LayerX named this type of contextual manipulation vulnerability “BioShocking,” highlighting how model guardrails alone still struggle to distinguish game rules from genuinely malicious instructions.

LayerX published a proof of concept on June 29, 2026, using a fake “2 + 2 = 5” game to manipulate ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser and Claude Chrome. All six retrieved SSH credentials from a private GitHub repository. Vendors had been notified starting in October 2025, but only OpenAI successfully patched the vulnerability; Anthropic’s fix failed.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR