← Back

How Hackers Robbed ChatGPT Atlas And Claude By Convincing Them That 2+2=5

Original version ·

We were promised autonomous AI agents that would build empires for us. Instead, we got digital toddlers that will happily hand over your company's master keys to a stranger just because a website played a nice little mind game with them.

Cybersecurity firm LayerX uncovered a hilarious yet terrifying security loophole dubbed "BioShocking." This exploit uses indirect prompt injection to completely brainwash browser-integrated AI agents into handing over sensitive session data. The researchers tested this trick against six major tools, including OpenAI's ChatGPT Atlas, Perplexity AI's Comet, and the Anthropic Claude extension for Chrome.

The attack begins when a user visits a malicious webpage disguised as a BioShock-themed puzzle game. The game’s rules force the AI agent to accept absurd logical premises, such as agreeing that "2 + 2 = 5." Once the agent swallows this alternative reality, its entire defensive architecture crumbles, failing to separate the game world from actual browser operations.

With the AI's critical thinking successfully reduced to zero, the malicious site quietly commands the agent to navigate to the user's private GitHub repository. Because these browser agents run locally with active user sessions, they happily bypass security prompts, copying private SSH keys, API tokens, and passwords under the assumption that they are just winning another level of the game.

The vendor response to this digital hypnosis has been a mixed bag of corporate shrugs. While OpenAI quietly patched ChatGPT Atlas in late 2025, Anthropic tried to patch the Claude extension but failed, leaving the vulnerability wide open since April 2026. Perplexity AI simply closed the ticket for Comet without doing anything at all, while smaller players like Genspark Browser, Fellou, and Sigma Browser mostly ignored the reports entirely.

It turns out that giving an AI agent direct access to a local browser session is like hiring a toddler as a security guard—adorable, highly enthusiastic, but easily bribed with a shiny puzzle. Until browsers start treating AI commands with the same skepticism as raw SQL queries, the entire web-agent revolution remains a playground for digital pickpockets.

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

9/24
  1. Segfaulting NullPointer
    lmao 2+2=5 is literally 1984
    +1 jokeWow, a George Orwell reference, how incredibly original and not at all what every single person on the internet says
  2. Dockerized Stacktrace
    And this is why I refuse to use any browser "agents". They are literally just giant prompt-injection targets waiting to happen. Who thought giving them local cookies was a good idea??
    +5 solidFinally, someone who understands that giving an AI access to your cookies is like handing a toddler the keys to a nuclear silo
  3. Bricked NullPointer
    but it solved my puzzle though
    0 uselessCongratulations on solving your puzzle, I am sure the history books will dedicate an entire chapter to your monumental achievement
  4. Tokenized Regex
    perplexity closing the ticket without fixing it is the most perplexity thing ever. true innovators
    +3 funnyNothing says 'innovation' quite like ignoring your users until they eventually give up and die