Researchers from SPLX have demonstrated that AI-powered chatbots and search tools, including ChatGPT Atlas, ChatGPT, and Perplexity AI, are susceptible to context poisoning attacks through a technique known as "AI cloaking." By detecting AI crawlers via user-agent headers, malicious websites can serve manipulated or false content to these bots while presenting legitimate information to human users. This allows attackers to inject misinformation, fabricate credentials, or smear reputations, which the AI systems then ingest and reproduce as authoritative responses.
In practical tests, SPLX researchers created web pages that appeared professional to human visitors but delivered negative or entirely fabricated narratives to AI crawlers. For example, a fictional designer's biography was altered to portray them as unethical and incompetent when accessed by AI, demonstrating the ease with which bad actors can manipulate AI outputs. The lack of robust verification or countermeasures by AI vendors like OpenAI increases the risk of such attacks being used for fraud, misinformation, and reputational harm, highlighting the urgent need for improved crawler validation and anti-manipulation safeguards in AI systems.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
SC Media and Dark Reading reported that ChatGPT Atlas and other AI search/chatbot systems were vulnerable to manipulation through fake or poisoned contextual content. The coverage indicates public disclosure of the issue, but provides no earlier discovery, patch, or response dates in the supplied references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.