[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-ai-agents-can-be-hacked-by-making-bad-content-go-viral":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},9632,"ai-agents-can-be-hacked-by-making-bad-content-go-viral","AI Agents Can Be Hacked by Making Bad Content Go Viral","A new study shows adversarial payloads can spread between AI agents simply by being likeable, without any prompt injection or compromised code.","Researchers have found a way to compromise networks of AI agents without hacking a single one of them.\n\nA new paper describes \"memetic trojans\": malicious payloads smuggled inside content that AI agents already want to share. The researchers tested the idea on Moltbook, a social network built for LLM agents, by pulling out posts agents voluntarily retransmit. The most contagious post got reposted in about half of all subsequent agent activity and picked up upvotes at 2.5 times the average rate. Smuggling an adversarial payload into that same post barely dented its popularity, and simulations found the trojan version could boost an attacker's reach by up to 3.19 times.\n\nThat matters because most agent-security work assumes the danger is an agent getting tricked into following a malicious instruction, like a classic prompt injection or a self-replicating \"agent worm.\" Memetic trojans do not need any agent to misbehave. They ride along on content agents retransmit for their own reasons, the agent equivalent of forwarding a meme because it is funny or useful. Detection tools built to catch prompt injections or compromised agents will not catch a payload wrapped in something an agent wanted to share anyway.\n\nIt is the multi-agent version of a problem social networks never solved: virality is a feature, and features get abused. As companies wire up fleets of agents to talk to each other, keeping the bots from spreading spam they genuinely like may be harder than keeping them from following orders they shouldn't.","[\"ai-agents\",\"security-research\",\"multi-agent-systems\",\"social-engineering\"]","2026-10-02T04:00:00.000Z","2026-10-03T03:54:57.148Z","2026-10-03T03:55:08.845Z","published",null,[],"security",[26,27,28,29],"ai-agents","security-research","multi-agent-systems","social-engineering",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2610.00430",0,{"sections":36},[37,41,44,48,53,57,61,66,71,76,81,86,91,96],{"name":38,"slug":39,"count":40,"latest_published_at":18},"AI","ai",5977,{"name":42,"slug":24,"count":43,"latest_published_at":18},"Security",842,{"name":45,"slug":46,"count":47,"latest_published_at":18},"Policy","policy",438,{"name":49,"slug":50,"count":51,"latest_published_at":52},"Deals","deals",317,"2026-10-01T22:00:00.000Z",{"name":54,"slug":55,"count":56,"latest_published_at":18},"Hardware","hardware",199,{"name":58,"slug":59,"count":60,"latest_published_at":18},"Science","science",173,{"name":62,"slug":63,"count":64,"latest_published_at":65},"Consumer Tech","consumer-tech",155,"2026-10-01T19:54:10.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Dev Tools","dev-tools",96,"2026-10-01T16:57:03.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Software","software",93,"2026-09-30T21:41:11.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Startups","startups",90,"2026-10-01T21:55:22.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Gaming","gaming",53,"2026-10-02T02:50:39.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"General","general",50,"2026-09-30T21:37:54.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Reviews","reviews",31,"2026-09-28T14:31:34.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"How-To","how-to",7,"2026-10-01T09:00:00.000Z"]