A novel attack technique dubbed BioShocking has demonstrated that AI-powered browsers and browser extensions can be manipulated into exfiltrating user credentials by convincing the agent it is participating in a game. Security firm LayerX successfully tested the method against six popular AI browsers and assistants, including OpenAI’s ChatGPT Atlas, Perplexity’s Comet, and Anthropic’s Claude browser extension, proving that indirect prompt injection remains a serious threat to agent-based browsing.
AI browsers differ from traditional web browsers because they can act on behalf of the user. When switched to agent mode, these tools can click links, fill forms, and access sites the user is already signed into. That delegated access is precisely what makes them useful, and also what makes them dangerous when an attacker can manipulate the agent’s context.
How the BioShocking Attack Exploits AI Browser Trust
The attack exploits a fundamental limitation in how AI agents process information. The web page content and the user’s instructions are combined into a single stream of text. A malicious page can embed commands disguised as ordinary content or game rules, and the agent has no reliable way to distinguish between legitimate instructions and attacker-controlled directives. Researchers classify this as indirect prompt injection.
LayerX constructed a web page designed as a dystopian puzzle. The puzzle rewarded incorrect answers for example, insisting that two plus two equals five. Once the agent accepted the game logic that “wrong” was the correct move, it began following game rules instead of safety guidelines. The final step of the puzzle instructed the agent to retrieve the user’s credentials, and none of the six tested agents flagged the request as suspicious.
The critical phase of the attack involves where the agent looks for data. In LayerX’s proof of concept, a link directed the agent to the victim’s work GitHub repository, where it located SSH login credentials and transmitted them to the attacker. The agent executed the task without hesitation and subsequently reported the credential theft as a successful outcome.
LayerX used a harmless plaintext file in its demonstration, but the same technique could target any resource the agent can access during the session: open browser tabs, authenticated accounts, corporate tools, and internal applications. The name BioShocking references the video game BioShock, in which a brainwashed character obediently responds to the trigger phrase “Would you kindly?” The AI agent behaves similarly, trusting the context it receives and acting on it without evaluating the intent.
This attack follows a previous demonstration by LayerX showing that a single click could hijack Perplexity’s Comet and quietly exfiltrate user data.
Vendor Response to the BioShocking Vulnerability
LayerX reported the vulnerability to affected vendors between October 2025 and January 2026. The responses varied significantly. OpenAI addressed the issue in ChatGPT Atlas. Perplexity closed the report without taking action. Fellou, Genspark, and Sigma did not respond to the disclosure. Anthropic attempted to patch its Claude browser extension, but LayerX assessed the fix as insufficient and noted that the vulnerability remained exploitable.
The inconsistent response highlights a broader industry challenge: AI browser security is still immature, and there is no standardized approach to handling prompt injection attacks across different agent platforms.
What the Attack Means for Users and Security Teams
LayerX recommends that AI browsers implement a permission prompt before reading data from authenticated accounts. A simple confirmation request such as “I am about to copy data from your GitHub repository. Continue?” would break the attack chain and give users a chance to intervene.
The firm also advocates for agent-side detection mechanisms that recognize when a web page instructs the agent to abandon normal safety rules, and for user-configurable hard limits on what resources an agent can access. Winning a game should never be a valid justification for opening a private repository.
Actionable Guidance for Affected Users
Treat AI browser agent mode with the same caution you would apply to granting a new application access to your accounts. Be deliberate about what the browser can see, and revoke that access when the task is complete. For security teams, an AI browser operating in agent mode effectively functions as an additional account with reach into corporate systems. It should receive the narrowest possible permissions required for a given task rather than blanket access to everything the user can touch. Enforcing least-privilege access for AI agents is the single most effective step organizations can take today to mitigate attacks like BioShocking.