{"id":2458,"date":"2026-07-10T03:13:56","date_gmt":"2026-07-10T03:13:56","guid":{"rendered":"https:\/\/xrpfaucet.site\/?p=2458"},"modified":"2026-07-10T03:13:56","modified_gmt":"2026-07-10T03:13:56","slug":"ai-agents-could-be-turned-into-botnets-through-hallucinations-researchers-warn","status":"publish","type":"post","link":"https:\/\/xrpfaucet.site\/?p=2458","title":{"rendered":"AI Agents Could Be Turned Into Botnets Through Hallucinations, Researchers Warn"},"content":{"rendered":"<div class=\"crypto-article\">\n<p>\ud83d\udcf0 <strong>Exclusive Crypto News &#038; Analysis:<\/strong> Stay ahead with the latest developments in the cryptocurrency and blockchain space.<\/p>\n<p>\ud83d\udcc8 <strong>Market Update:<\/strong> Real-time price movements, technical analysis, and trading signals.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/img.decrypt.co\/insecure\/rs:fill:1024:512:1:0\/plain\/https:\/\/cdn.decrypt.co\/wp-content\/uploads\/2026\/02\/test-2-gID_7.png@png\" \/><\/p>\n<div style=\"position:relative;overflow:visible;font-size:1.2em;line-height:1.58\">\n<div class=\"pt-8 pb-10 border-t border-b border-decryptGridline \">\n<h4 class=\"sc-b2a202e4-4 bNRGqr gg-dark:text-white\" color=\"#333\">In brief<\/h4>\n<ul>\n<li class=\"font-meta-serif-pro font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Researchers introduced \u201cAdversarial HalluSquatting,\u201d an attack that exploits AI-generated hallucinations.<\/li>\n<li class=\"font-meta-serif-pro font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">The technique tricks AI agents into trusting fake repositories or tools that contain malicious instructions.<\/li>\n<li class=\"font-meta-serif-pro font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Tests against popular AI coding assistants showed the method could lead to remote code execution in controlled experiments.<\/li>\n<\/ul>\n<\/div>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">AI hallucinations may be more than incorrect answers\u2014they could become a way for hackers to compromise computers, according to new research from Tel Aviv University, Technion, and Intuit.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">In the <a href=\"https:\/\/arxiv.org\/html\/2607.07433v1\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">paper<\/a>\u201cBeware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting,\u201d researchers demonstrated a technique that exploits AI models when they generate fake links to software repositories and other online resources.<\/p>\n<p><iframe loading=\"lazy\" style=\"border:0\" src=\"https:\/\/myriad.markets\/embed\/market\/who-ipos-first-d112e68a-b7d1-4991-9f77-ca2db82cdc99\" width=\"100%\" height=\"415px\"><span style=\"display:inline-block;width:0px;overflow:hidden;line-height:0\" data-mce-type=\"bookmark\" class=\"mce_SELRES_start\">\ufeff<\/span><\/iframe><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cThe growing adoption of agentic LLM applications has introduced a new threat previously named as promptware,\u201d the researchers wrote. \u201cWhile prior work has established that adversaries can exploit direct channels to LLM applications to apply promptware under weak threat models, many applications do not provide any direct channels that could be exploited for prompt injection beyond the Internet.\u201d<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Known as adversarial hallucination squatting or \u201cHalluSquatting,\u201d the attack involves predicting which fake resources AI models are likely to create, registering those names, and adding malicious instructions. If an AI agent later retrieves the hallucinated resource, it may treat the attacker-controlled content as legitimate.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">The researchers said the threat emerges as AI assistants move beyond answering questions and gain the ability to interact with computers\u2014accessing files, searching the web, writing code, and running commands.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Those abilities can create security gaps when agents act on information they retrieve without confirming whether the source is real.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cOngoing studies have demonstrated various variants of Promptware attacks against real-world systems, including ChatGPT, Google Assistant, Copilot, and various additional applications,\u201d they wrote. \u201cThese works demonstrated that Promptware can lead to financial, privacy, and safety impacts.\u201d<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Researchers warned the technique could allow attackers to build AI-enabled botnets. A <a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-botnet\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">botnet <\/a>refers to a network of infected computers or devices controlled remotely by an attacker. Botnets are commonly used in cyberattacks, including denial-of-service attacks, <a href=\"https:\/\/decrypt.co\/331195\/cryptojacking-resurfaces-as-monero-miner-malware-hits-3500-sites-report\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">cryptocurrency mining<\/a>, <a href=\"https:\/\/decrypt.co\/370557\/ai-malware-worm-adapts-targets-cybersecurity\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">malware distribution<\/a>and <a href=\"https:\/\/decrypt.co\/354731\/deadlock-ransomware-using-polygon-smart-contracts-to-evade-detection\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">ransomware<\/a> campaigns.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">In testing, the researchers found AI-generated resource hallucinations occurred at rates as high as 85% in repository cloning scenarios and 100% in skill installation tests.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">The team evaluated the technique against AI coding assistants and agents, including <a href=\"https:\/\/decrypt.co\/371308\/spacex-new-high-as-elon-musk-firm-agrees-acquire-ai-startup-cursor\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">Cursor<\/a>, <a href=\"https:\/\/decrypt.co\/320961\/microsoft-introduces-github-ai-agent-now-with-more-vibe-coding\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">GitHub Copilot<\/a>, <a href=\"https:\/\/decrypt.co\/368389\/google-gemini-spark-ai-agent-challenge-hermes-openclaw\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">Gemini<\/a> CLI, and <a href=\"https:\/\/decrypt.co\/356730\/openclaw-ai-agents-whats-real\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">OpenClaw<\/a>.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">HalluSquatting is similar to <a href=\"https:\/\/en.wikipedia.org\/wiki\/Typosquatting\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">typosquatting<\/a>a cyberattack tactic where attackers register domain names resembling legitimate websites or software packages to trick users. Instead of exploiting human typing mistakes, HalluSquatting targets mistakes made by AI models.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">The news comes as researchers continue to test how attackers can manipulate AI agents.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">In April, Google researchers <a href=\"https:\/\/decrypt.co\/365677\/google-prompt-injection-ai-agents-paypal-enterprise\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">detailed<\/a> malicious websites designed to hijack AI agents through indirect prompt injection attacks, including attempts to steal passwords, delete files, and manipulate payments. A separate study on the \u201c<a href=\"https:\/\/decrypt.co\/338143\/copypasta-attack-shows-prompt-injections-infect-ai-scale\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">CopyPasta<\/a>\u201d attack showed how hidden prompts inside developer files could manipulate AI coding assistants into spreading malicious code.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">In June, an OpenClaw user reported facing more than <a href=\"https:\/\/decrypt.co\/372221\/ai-agent-openclaw-6000-hack-attempts\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">6,000<\/a> attempts from attackers attempting to trick the AI agent into leaking sensitive information.<\/p>\n<div class=\"my-4 border-b border-decryptGridline\">\n<div class=\"text-start p-8 md:py-12 md:px-12 max-w-prose relative\"><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-(6px) md:border-l-(6px) md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute top-4 left-4 md:top-6 md:left-6\"\/><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-(6px) md:border-l-(6px) md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute rotate-180 bottom-4 right-4 md:bottom-6 md:right-6\"\/><\/p>\n<h3 class=\"font-akzidenz-grotesk font-bold text-xl md:text-3xl md:text-center gg-dark:text-white\">Daily Debrief<!-- --> Newsletter<\/h3>\n<p>Start every day with the top news stories right now, plus original features, a podcast, videos and more.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>\ud83d\udca1 <strong>Pro Tip:<\/strong> Bookmark our site for daily insights, market predictions, and expert trading strategies.<\/p>\n<p>\ud83d\udd17 <strong>Explore More:<\/strong> Check our sections for in-depth guides, exchange reviews, and blockchain technology deep-dives.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ud83d\udcf0 Exclusive Crypto News &#038; Analysis: Stay ahead with the latest developments in the cryptocurrency and blockchain space. \ud83d\udcc8 Market Update: Real-time price movements, technical analysis, and trading signals. In brief Researchers introduced \u201cAdversarial HalluSquatting,\u201d an attack that exploits AI-generated hallucinations. The technique tricks AI agents into trusting fake repositories or tools that contain malicious &hellip;<\/p>\n","protected":false},"author":1,"featured_media":2459,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","footnotes":""},"categories":[10],"tags":[],"class_list":["post-2458","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/posts\/2458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2458"}],"version-history":[{"count":0,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/posts\/2458\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/media\/2459"}],"wp:attachment":[{"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}