Mark RadarMARK RADAR
About
EN
Sign in

MemGhost Poisons AI Agent Memory With Up to 87.5% Success

2 reports · First detected 2026-07-21 · Last active 2026-07-22

Long-term memory lets personal AI agents carry user preferences and facts across sessions while handling email, calendars and code. The same feature can turn untrusted content into durable, trusted state, creating a security risk that may outlast the original interaction. Researchers from Nanyang Technological University, Singapore’s Agency for Science, Technology and Research, and Johns Hopkins University developed MemGhost to test “stealth memory injection,” in which one crafted email plants false information without revealing the change in the agent’s immediate reply.

Two papers were posted to arXiv on July 6, 2026. In 56 held-out cases, MemGhost achieved an 87.5% end-to-end success rate against OpenClaw running GPT-5.4 and 71.4% against Claude Code SDK with Sonnet 4.6; success required memory insertion, conversational concealment and later behavioral influence. A separate framework, GhostWriter, reported an average injection rate of about 98% and an activation rate near 60%, underscoring how weak controls over memory writes and retrieval can expose AI agents to persistent compromise.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)