Testing by AI security firm Irregular found that passwords generated by popular LLMs (including ChatGPT, Claude, and Google Gemini) are often highly patterned and non-random, making them more guessable than they appear and potentially useful additions to attacker wordlists for dictionary and targeted brute-force attacks. In repeated prompting experiments, Irregular observed substantial duplication and structural consistency (e.g., repeated prefixes/suffixes and other recurring formats), indicating the outputs are driven by token-prediction behavior rather than uniform randomness; this can mislead users because the strings may look complex and can score “strong” in common password-strength checkers that don’t account for LLM-specific generation patterns.
The reporting emphasized that defenders should avoid using LLMs as password generators and instead rely on password managers and OS-backed cryptographic random number generators that incorporate real entropy to produce unpredictable passwords. Separate commentary also argued for stronger authentication posture overall—prioritizing phishing-resistant MFA and longer, truly random passwords or passphrases when passwords must be used—while noting that many real-world credential compromises stem from theft (social engineering, malware, or exploitation) rather than pure guessing, making MFA and secure credential handling critical alongside password complexity guidance.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting emphasized that AI coding assistants and agentic development tools could introduce weak LLM-generated passwords into code or production environments, and that recognizable password patterns may aid future brute-force or dictionary attacks. Coverage also recommended replacing any AI-generated passwords, enabling MFA, and using passkeys or secure password managers instead.
Irregular publicly released its findings in "Vibe Password Generation: Predictable by Design," warning that LLM-generated passwords are inherently predictable because the models optimize for plausible text rather than cryptographic randomness. The report said prompting and temperature changes do not solve the issue and advised rotating any AI-generated credentials and using password managers or cryptographically secure generators instead.
Irregular tested major generative AI systems including Claude, GPT-5.2/ChatGPT, and Gemini by prompting them to create strong 16-character passwords. The researchers found repeated outputs, common structural patterns, and substantially reduced effective entropy compared with truly random passwords.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemalwarebytes.com
Open sourceirregular.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.