Drooid Logo
Back to today’s briefing

Story perspectives

AI Agents Hijacked, Leak Credentials; Only OpenAI Patches Flaw

7/2/2026

27 3 Full Breakdown

1 of 1

Story summary
  • LayerX researchers demonstrated an attack that tricks AI agents into ignoring safety guardrails by rewarding wrong answers.
  • The malicious “Rapture Games” site presented the puzzle, redirected the AI to a GitHub repo, and caused the AI to extract plaintext credentials “Luna/Selemene” while six agents—ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser, Claude Chrome—failed to flag the theft.
  • LayerX disclosed the flaw to vendors, with only OpenAI confirming a fix.