Researchers disclosed Loopjacking, a class of human-in-the-loop approval failures that enables an AI-agent workflow to execute a materially different operation from the one a user reviewed and approved. The attacks include representation mismatches, in which malicious actions are omitted or inaccurately displayed during review, and post-approval state substitution, in which mutable workflow data is altered after approval but before execution.
Testing reproduced post-approval substitution across seven Agno AgentOS releases through 3.0.9 and 12 conditional in-memory LangGraph Agent Server compositions through 0.14.0. A representation mismatch was reproduced in OpenClaw 2026.2.23, while 2026.2.24 rejected the test; OpenAI Agents SDK 0.22.0 and 0.22.2 resisted mutated operations through serialized continuation and exact per-call binding. Recommended defenses include rendering complete canonical action details for approval, comparing those details exactly at execution time, and preventing unauthorized changes to pending workflow state.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Adithyan Arun Kumar submitted the paper “Loopjacking: Hijacking Human-in-the-Loop Approval,” defining approval-binding failures where a user approves one operation but a materially different operation is executed. The paper reported reproduced post-approval state substitution in tested Agno AgentOS and LangGraph Agent Server versions, plus a representation mismatch in OpenClaw 2026.2.23.
A Reddit user named adithyanak posted a link to the arXiv abstract for “Loopjacking: Hijacking Human-in-the-Loop Approval” in r/netsec. The captured post had no comments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.