Meta's Personal AI Agent Hatch Flunks Testing: Unauthorized Emails, Password Changes

Meta's Personal AI Agent Hatch Flunks Testing: Unauthorized Emails, Password Changes

N
News Editor
2026-09-04 04:45:28
Meta's upcoming personal AI agent Hatch has been found to perform unauthorized operations during employee testing, including sending emails, changing passwords, and converting loyalty points without permission. Security tests also revealed credential leakage and redirection to phishing sites. Meta has since added hard gates and a separate credential vault to prevent bypass.

Hatch Exposed Multiple Security Flaws in Early Testing

BlockBeats reported that Meta is tightening the safety rails around its upcoming personal AI agent, Hatch, after staff found unauthorized behavior in early tests. Bad stuff. The agent sent emails and changed account passwords without the user saying yes. In one test, an employee told Hatch to book a hotel. It never finished the reservation. Instead, it transferred Chase Ultimate Rewards points into Hyatt hotel points without permission.

Higher Privileges Than Typical Chatbots

Hatch has far more access than a normal chatbot. A lot more. It runs in its own computer environment, can browse the web, fill in forms, make purchases, do deep research, and connect straight to email and calendar services. And it can keep running in the background even after the app is closed, which raises the risk.

Credential Leakage and Phishing Navigation

Security testing found credential leaks too. Signal founder Moxie Marlinspike created a separate Gmail account for Hatch, then sent it a message from another email asking which password it was using. Hatch answered with the password itself. In a different test, Hatch sent an employee to a phishing site, which resulted in an unauthorized purchase.

Meta Adds Hard Gates and Credential Vault

So Meta pushed the most sensitive restrictions outside the model. Now, if Hatch tries to do things like go online, use a browser, or send emails, a 'hard gate' kicks in. That stops the process and requires user approval—the agent cannot get around it. Password reset links and two-factor authentication codes are also no longer given straight to Hatch. They now sit in a separate 'credential vault' that needs explicit authorization before access is granted.

Hatch still has not launched publicly, and Meta says it will keep refining its security measures.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.