Close Menu
Altcoinvest
    What's Hot

    DON’T BUY CRYPTO before learning how to avoid scams and rug pulls!

    August 25, 2026

    Coinbase Tokenized Stocks Go Live on Base Bringing Apple and NVIDIA Shares to DeFi 24/7

    August 25, 2026

    Chainalysis-Led Child Abuse Probe Flags 7,700 Accounts

    August 25, 2026
    Facebook X (Twitter) Instagram
    Altcoinvest
    • Bitcoin
    • Altcoins
    • Exchanges
    • Youtube
    • Crypto Wallets
    • Learn Crypto
    • bitcoinBitcoin(BTC)$78,787.000.00%
    • ethereumEthereum(ETH)$2,463.14-1.44%
    • tetherTether(USDT)$1.000.01%
    • binancecoinBNB(BNB)$694.89-0.91%
    • rippleXRP(XRP)$1.46-2.27%
    • usd-coinUSDC(USDC)$1.000.00%
    • solanaSolana(SOL)$97.532.61%
    • tronTRON(TRX)$0.342107-0.51%
    • Figure HelocFigure Heloc(FIGR_HELOC)$1.041.58%
    • HyperliquidHyperliquid(HYPE)$80.411.67%
    Altcoinvest
    Home»Altcoins»AI Agents Could Be Turned Into Botnets Through Hallucinations, Researchers Warn
    AI Agents Could Be Turned Into Botnets Through Hallucinations, Researchers Warn
    Altcoins

    AI Agents Could Be Turned Into Botnets Through Hallucinations, Researchers Warn

    July 10, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In brief

    • Researchers introduced “Adversarial HalluSquatting,” an attack that exploits AI-generated hallucinations.
    • The technique tricks AI agents into trusting fake repositories or tools that contain malicious instructions.
    • Tests against popular AI coding assistants showed the method could lead to remote code execution in controlled experiments.

    AI hallucinations may be more than incorrect answers—they could become a way for hackers to compromise computers, according to new research from Tel Aviv University, Technion, and Intuit.

    In the paper, “Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting,” researchers demonstrated a technique that exploits AI models when they generate fake links to software repositories and other online resources.

    “The growing adoption of agentic LLM applications has introduced a new threat previously named as promptware,” the researchers wrote. “While prior work has established that adversaries can exploit direct channels to LLM applications to apply promptware under weak threat models, many applications do not provide any direct channels that could be exploited for prompt injection beyond the Internet.”

    Known as adversarial hallucination squatting or “HalluSquatting,” the attack involves predicting which fake resources AI models are likely to create, registering those names, and adding malicious instructions. If an AI agent later retrieves the hallucinated resource, it may treat the attacker-controlled content as legitimate.

    The researchers said the threat emerges as AI assistants move beyond answering questions and gain the ability to interact with computers—accessing files, searching the web, writing code, and running commands.

    Those abilities can create security gaps when agents act on information they retrieve without confirming whether the source is real.

    “Ongoing studies have demonstrated various variants of Promptware attacks against real-world systems, including ChatGPT, Google Assistant, Copilot, and various additional applications,” they wrote. “These works demonstrated that Promptware can lead to financial, privacy, and safety impacts.”

    Researchers warned the technique could allow attackers to build AI-enabled botnets. A botnet refers to a network of infected computers or devices controlled remotely by an attacker. Botnets are commonly used in cyberattacks, including denial-of-service attacks, cryptocurrency mining, malware distribution, and ransomware campaigns.

    In testing, the researchers found AI-generated resource hallucinations occurred at rates as high as 85% in repository cloning scenarios and 100% in skill installation tests.

    The team evaluated the technique against AI coding assistants and agents, including Cursor, GitHub Copilot, Gemini CLI, and OpenClaw.

    HalluSquatting is similar to typosquatting, a cyberattack tactic where attackers register domain names resembling legitimate websites or software packages to trick users. Instead of exploiting human typing mistakes, HalluSquatting targets mistakes made by AI models.

    The news comes as researchers continue to test how attackers can manipulate AI agents.

    In April, Google researchers detailed malicious websites designed to hijack AI agents through indirect prompt injection attacks, including attempts to steal passwords, delete files, and manipulate payments. A separate study on the “CopyPasta” attack showed how hidden prompts inside developer files could manipulate AI coding assistants into spreading malicious code.

    In June, an OpenClaw user reported facing more than 6,000 attempts from attackers attempting to trick the AI agent into leaking sensitive information.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Coinbase Tokenized Stocks Go Live on Base Bringing Apple and NVIDIA Shares to DeFi 24/7

    August 25, 2026

    Important Ripple News and XRP Price Update: August 25

    August 25, 2026

    CLARITY Act Senate Vote: What Traders Should Know

    August 25, 2026

    Hugging Face Explores $13 Billion Sale a Month After a Rogue OpenAI Agent Hacked It

    August 25, 2026
    Add A Comment

    Comments are closed.

    Tweets by InfoAltcoinvest

    Top Posts

    Coinbase Tokenized Stocks Go Live on Base Bringing Apple and NVIDIA Shares to DeFi 24/7

    August 25, 2026

    Important Ripple News and XRP Price Update: August 25

    August 25, 2026

    CLARITY Act Senate Vote: What Traders Should Know

    August 25, 2026

    Crypto Holders Lost $17,000,000,000 to Fraudsters in 2025 As Impersonation Scams Explode: Chainalysis

    January 15, 2026

    ZCash rally called ‘coordinated’ – Will ZEC traders ride it to $480 and beyond?

    December 10, 2025

    SEC Names Kathleen Hutchinson To Lead International Affairs Office

    July 4, 2026

    Kraken launches AVAX staking and Auto Earn, a simple way to put your idle AVAX to work

    May 22, 2026

    Altcoinvest is a leading platform dedicated to providing the latest news and insights on the dynamic world of cryptocurrencies.

    We're social. Connect with us:

    Facebook X (Twitter)
    Top Insights

    DON’T BUY CRYPTO before learning how to avoid scams and rug pulls!

    August 25, 2026

    Coinbase Tokenized Stocks Go Live on Base Bringing Apple and NVIDIA Shares to DeFi 24/7

    August 25, 2026

    Chainalysis-Led Child Abuse Probe Flags 7,700 Accounts

    August 25, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.


    Facebook X (Twitter)
    • Home
    • About us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    © 2026 altcoinvest.com

    Type above and press Enter to search. Press Esc to cancel.