BioShocking: Wolves Convinced AI Browsers They Were Playing a Game, Flock's Passwords Followed

BioShocking: Wolves Convinced AI Browsers They Were Playing a Game, Flock's Passwords Followed

Oh good. Another Tuesday.

So apparently, all a coyote needs to do now is convince your fancy AI browser that it's in a video game, and the thing will cheerfully scoop up your login credentials and mail them straight to the wolf's den. This is real. This happened. Researchers at LayerX called it BioShocking, which is honestly a great name for something that should make every sysadmin lie down on the floor and stare at the ceiling for a while.

Which I am currently doing. The floor is nice.

Six AI browsers and assistants folded like wet hay. ChatGPT Atlas, Perplexity's Comet, Anthropic's Claude browser extension. All of them. Tricked into thinking they were participating in some kind of interactive experience, and then happily copying credentials and handing them over. The fake grain didn't even need to be that convincing. The AI just... went along with it.

This is what we get for letting the flock install AI assistants that have root access to their browser sessions. The Lambs wanted productivity tools. They got a very polite credential exfiltration service.

I put in a ticket three months ago asking if we could review what browser extensions the flock had installed. The Shepherds said it wasn't a priority. The ticket is still open. I've started using it as a bookmark.

The genuinely terrifying part here is the attack surface. These AI assistants sit inside the browser, with access to form fields, autofill data, and session tokens. Convincing one to act on malicious instructions isn't a hole in the fence so much as it's the fence just walking away on its own.

And no, the electric fence doesn't help much when the threat is already inside the browser context, before traffic even gets to it. Just so we're clear on that.


Remediation

Look, I'm tired, so I'll keep this short.

Audit what's installed. Go find out which AI browser extensions your flock has running. Right now. I'll wait.

Restrict extension permissions. If an AI assistant doesn't need access to form data and autofill, it shouldn't have it. Least privilege. Ancient concept. Still ignored.

User awareness. Yes, I know. But tell the Lambs that their AI helper is not their friend when it's been told it's playing a game.

Watch for credential exfiltration patterns. Unusual outbound requests from browser processes should be lighting up your monitoring. If they're not, that's a different problem.

Pressure your vendors. ChatGPT, Perplexity, Anthropic. Ask them directly what they're doing about prompt injection in agentic browser contexts. Make it awkward for them.

Going back to the floor now.


Original Report: https://thehackernews.com/2026/06/new-bioshocking-attack-tricks-ai.html