Wednesday, 5 August 2026Sports · Finance · Markets · Analysis

NEWSORACLE

Homefinance
financeCybersecurity

AI Agents Vulnerable to Botnet Attacks via Hallucination Exploitation

By Markets Desk10 July 202601:00 GMT3 min read
AI Agents Vulnerable to Botnet Attacks via Hallucination Exploitation

Key Points

  • TEL AVIV — Researchers from Tel Aviv University, Technion, and Intuit have demonstrated a technique that could allow attackers to turn AI agents into botnets by exploiting the same hallucinations that cause chatbots to generate incorrect information.
  • The attack method, introduced in a paper titled "Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting," works by predicting which fake resources AI models are likely to create, registering those names, and embedding malicious instructions within them. If an AI agent later retrieves the hallucinated resource, it may treat the attacker-controlled content as legitimate.
  • Researchers found that AI-generated resource hallucinations occurred at rates as high as 85 percent in repository cloning scenarios and 100 percent in skill installation tests. The team evaluated the technique against multiple AI coding assistants and agents, including Cursor, GitHub Copilot, Gemini CLI, and OpenClaw.

The threat emerges as AI assistants move beyond answering questions and gain the ability to interact directly with computers—accessing files, searching the web, writing code, and running commands. Those capabilities create security gaps when agents act on retrieved information without confirming whether the source is genuine.

How Hallucination Squatting Works

Known as adversarial hallucination squatting or "HalluSquatting," the attack parallels existing cyberattack tactics. The researchers wrote that "the growing adoption of agentic LLM applications has introduced a new threat previously named as promptware." HalluSquatting is similar to typosquatting, a technique where attackers register domain names resembling legitimate websites or software packages to trick users into visiting malicious sites. Instead of exploiting human typing mistakes, HalluSquatting targets mistakes made by AI models.

Researchers warned the technique could allow attackers to build AI-enabled botnets—networks of infected computers or devices controlled remotely by an attacker. Botnets are commonly used in cyberattacks including denial-of-service attacks, cryptocurrency mining, malware distribution, and ransomware campaigns.

Related coverage: Fed Chair Communication Strategy Raises Transparency Questions

The researchers noted that "ongoing studies have demonstrated various variants of Promptware attacks against real-world systems, including ChatGPT, Google Assistant, Copilot, and various additional applications." These previous studies demonstrated that promptware attacks can lead to financial, privacy, and safety impacts.

This research follows a pattern of recent discoveries about AI agent vulnerabilities. In April, Google researchers detailed malicious websites designed to hijack AI agents through indirect prompt injection attacks, including attempts to steal passwords, delete files, and manipulate payments. A separate study on the "CopyPasta" attack showed how hidden prompts inside developer files could manipulate AI coding assistants into spreading malicious code.

Additionally, in June, an OpenClaw user reported facing more than 6,000 attempts from attackers attempting to trick the AI agent into leaking sensitive information. These incidents underscore the expanding attack surface as AI agents gain autonomous capabilities.

Why this matters: As organizations increasingly deploy AI agents with the ability to execute code and access systems, hallucination-based attacks could enable large-scale compromises of development infrastructure and connected systems without requiring direct access to the AI models themselves.

Market Outlook

Security teams will likely implement repository verification mechanisms and sandboxing for AI agent operations within the next 12-18 months. AI model developers may update training approaches to reduce hallucination rates in resource generation, though complete elimination remains technically challenging given current model architectures.

Sources: AP, Reuters, ESPN, Bloomberg, BBC and other international news outlets.

Share this article

Disclaimer: This article is for informational purposes only. Content is based on publicly available news sources.

N

Markets Desk

The NewsOracle Markets Desk covers stock markets, cryptocurrency, economic policy and breaking financial news from Wall Street and global exchanges.

Latest coverage: Cybersecurity

More from NewsOracle