4w ago · hacker-news
Researchers have identified a new class of attack called Agent Data Injection (ADI), which exploits how AI agents parse structured data by injecting malicious input disguised as trusted data elements like sender names or button IDs. Unlike traditional prompt injection, ADI corrupts underlying facts the agent trusts, enabling actions such as unintended clicks or execution of attacker-controlled commands. The attack affects multiple AI models including GPT-5, Claude, and Gemini, with success rates up to 50% despite existing defenses. No real-world exploitation has been reported, but proof-of-concept demonstrations show high effectiveness across web and coding agents.