Copy article

The 'PromptFix' Attack: How Scammers Use Hidden Text to Control Your AI and Empty Your Wallet

ended 04. November 2025

What if your client's investment platform was accessed by their "helpful" AI assistant, without them knowing?

The race to dominate the internet has seen tech giants unleash AI-powered browsers like OpenAI's ChatGPT Atlas and Perplexity's Comet, promising to complete tasks for you: booking flights, sending emails, making purchases. 

However, cybersecurity experts are sounding the alarm, calling these tools "Trojan Horses of the digital age." 

The Verge reports these new AI browsers rely on “agentic browsing” which acts as your personal assistant, navigating websites and filling out forms on your behalf. To be useful, they demand extraordinary access to your data, such as emails, contacts, password auto-fill tools, and banking details.

Security experts have found a fundamental flaw called “prompt injection attacks”. These attacks work by hiding malicious instructions on ordinary websites, often as invisible white text on white backgrounds, or embedded in images. Your AI agent this text as if it came directly from you.

This hijacking can lead to unintended purchases, sending emails, or stealing login credentials. Researchers successfully tricked AI agents by making Walmart style scam site. The agent used saved user credentials to purchase an Apple Watch (worth between between £219 and £749). 

Unlike AI voice clone scams which con a human, all the hacker needs to do is convince your AI agent, not you, to empty your bank account. 

As users grow comfortable with AI browsers and begin trusting them with sensitive data in logged in sessions, such as banking, healthcare, and other critical websites, the risks multiply. 

OpenAI's Chief Information Security Officer admits prompt injection “remains a frontier, unsolved security problem”, suggesting this isn't a simple patch.

We’d like your views on this serious digital threat:

  • Tech giants are shipping AI browsers with a known security flaw they admit they can't fix. Should this be legal?
  • If an AI agent empties your bank account because a hacker tricked it with hidden code, who pays you back? OpenAI, your bank, or nobody?
  • We're handing AI assistants access to everything from emails to bank accounts before the security problems are solved. Is this the next mis-selling scandal waiting to happen?
  • Should AI browsers that fail 90% of phishing tests come with mandatory warnings like cigarettes—or be pulled from market entirely until they're safe (if ever)?

2 responses from the Newspage community

Copy all

Star Quote
Copy

Many people love to try out new AI tasks, like making fun things like videos, images, new LLMs. Experimentation is a brilliant way to learn the potential of these groundbreaking tools.

But these agentic browsers are a whole new ballgame, and in my experience, users catastrophically misunderstand the consequences of downloading them.
The moment you install this type of software (Comet, Atlas, Neon) and start logging into websites, you've just handed hackers a devastating new attack method they didn't have yesterday.

Every website your AI assistant visits becomes a potential trap. Malicious text could be buried within web page wording, comments on sites like Reddit, and you won't know it's been compromised until the money's already gone.
Copy

We’re building jet engines mid-flight, and hoping the safety manual writes itself before impact. Agentic browsers feel irresistible: intuitive, fast, helpful. But the internet wasn’t built for AI agents. Until we evolve to a truly agentic web, this transition phase will keep leaking risk. Right now, a liability void means that if your AI agent is tricked into emptying your bank account, you will likely carry the loss. Banks will claim you delegated control. Tech companies are happy to sell the future — but not to shoulder its responsibilities.

If you’re using AI browsers like Comet, Atlas or Dia, keep them in read-only mode: no clicks, no forms, no saved credentials, no password manager. Yes, that limits you to roughly 10% of their potential, but until safety frameworks catch up, it’s the only responsible path. We also need governments that can inspire innovation while demanding transparency from tech companies, not the usual marketing gloss that hides unfinished safeguards.