AI Agents Think. They Just Don’t Know They’re Being Watched.

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A security researcher breaks down eight attack vectors for AI-powered applications — including prompt injection, indirect prompt injection, RAG poisoning, SSRF via AI browsing, and multi-modal injection — then details two critical vulnerabilities found in a crypto AI trading platform. The first was system prompt leakage: toggling a stream parameter to false returned the full internal response including a 14,000-token proprietary system prompt, model details, and agent architecture. The second was unauthenticated access to a GraphQL WebSocket endpoint that exposed the platform's entire paid trading signal feed to anyone without a login. Key takeaways include always testing WebSocket auth independently, flipping stream parameters, and checking GraphQL introspection in production.

9m read timeFrom infosecwriteups.com
Post cover image

Sort: