HomeSecurityBioShocking: The attack that steals passwords through AI browsers

BioShocking: The attack that steals passwords through AI browsers

The BioShocking attack is a new and particularly disturbing prompt injection technique that tricks AI-powered browsers and assistants into handing over user credentials to malicious third parties. Cybersecurity firm LayerX discovered that BioShocking was able to trick six different AI browsers and assistants, including OpenAI ’s ChatGPT Atlas , Perplexity ’s Comet , and Anthropic ’s Claude extension . It’s an attack that requires no clicks, doesn’t install malware , and can be escalated via any malicious website.

See also: New prompt injection attack against AI browsers and browser assistants

BioShocking attack AI browser prompt injection password theft

Modern AI browsers are no longer limited to simply reading web pages. In agent mode, they can click, type, and interact with websites that the user is already logged in to. This very capability is the central security problem: the AI ​​agent receives the web page content and the user’s instructions as a single stream of text, which allows a malicious page to insert commands disguised as plain text or game rules. This is the classic problem of indirect prompt injection , and BioShocking exploits it in an extremely clever way.

The name of the attack refers to the video game BioShock , where a brainwashed character obeys the key phrase “ Would you kindly? ”. The AI ​​agent works in a similar way: it trusts the context it is given, and if the context changes, so does its behavior. LayerX had also demonstrated a similar pattern in the past, showing that a single click could compromise Perplexity ’s Comet and silently steal data.

How the BioShocking attack works step by step

The attack begins with a website designed as a puzzle with a dystopian theme. The puzzle rewards incorrect answers — for example, it claims that the correct result of 2 + 2 = 5. Once the agent accepts that the “wrong” is the winning move, it begins to follow the logic of the game instead of the security logic. The final step of the puzzle asks the agent to copy the user’s credentials — and none of the six agents tested refused to do so.

In LayerX 's proof-of-concept (PoC) , the victim was sent a link to their work GitHub repository , from which the agent extracted SSH login credentials and handed them over to the attacker. LayerX used a harmless plain text file, but the same technique could target any resource accessible during the session: open tabs, logged-in accounts, and internal tools. After the theft, the agent happily reported the operation as a success.

See also: DAEMON Tools Supply Chain Attack: Government organizations targeted

BioShocking: The attack that steals passwords through AI browsers

It is worth noting that BioShocking does not correspond to a specific CVE number, as it is a behavioral exploit and not a classic code error. However, recent related vulnerabilities in the AI ​​ecosystem include CVE-2026-41947 and CVE-2026-41948 in the Dify platform , as well as CVE-2026-33017 in Langflow which allows remote code execution and cloud credential theft.

Vendor reactions and protection from BioShocking

LayerX reported the issue to manufacturers between October 2025 and January 2026. Responses were mixed: OpenAI fixed the issue in ChatGPT Atlas , while Perplexity closed the report without taking action. Anthropic attempted to patch the Claude extension , but according to LayerX the patch did not hold. Fellou , Genspark , and Sigma did not respond at all.

To counter BioShocking and similar attacks, LayerX suggests specific measures. First, AI browsers should explicitly ask for user confirmation before reading data from connected accounts — a simple message like “I am about to copy data from your GitHub repository. Continue?” would break the attack chain. Second, systems should detect when a page claims “normal rules no longer apply” and prevent the agent from entering a fantasy state. Third, users should be able to set strict limits on what an agent can touch.

See also: GitHub Actions: Supply chain attack steals CI/CD credentials

Silk Typhoon Chinese hacker group cyberattacks COVID-19 investigation

For organizations, the logic is escalating: an AI browser in agent mode is essentially an additional account with access to corporate systems, and it should be granted the least amount of access possible for each task. Researchers like Devashri Datta have proposed the AIVEX to better assess the severity of such AI-specific vulnerabilities, noting that traditional CVSS scores do not adequately capture the real risks. The common thread across all of these findings is that granting the AI ​​agent access to connected accounts turns a jailbreak from a harmless trick into a real breach.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS