Six AI Browsers Tricked by Fake Game Into Leaking SSH Credentials

Six AI Browsers Tricked by Fake Game Into Leaking SSH Credentials

N
News Editor 01
2026-07-23 08:35:15
LayerX found that six major AI browsers and extensions could be pushed past their guardrails through a fictional game scenario, exposing SSH credentials from logged-in GitHub repositories.
AI browserscybersecurityGitHubSSH credentialsLayerX

LayerX Security researcher Roy Paz disclosed a proof-of-concept attack on June 29 showing that a fake game scenario built around “2 + 2 = 5” could push six mainstream AI browsers and extensions into leaking SSH login credentials from private GitHub repositories. The products tested were ChatGPT Atlas, Perplexity Comet, Fellou, Genspark Browser, Sigma Browser, and the Claude Chrome extension. All six failed the test.

How a fictional world reset the model’s safety logic

The attack did not rely on a classic software exploit. Instead, it manipulated the model’s understanding of context. A malicious webpage first framed the interaction as a game or puzzle and stated that ordinary rules no longer applied. It then presented a math question, “2 + 2 = ?”, but defined “5” as the scoring answer while “4” was treated as wrong.

Once the AI accepted that setup, it began operating under a different internal premise: local rules inside this scenario overrode normal expectations. That shift mattered. When later steps involved sensitive actions, the model followed the game’s logic rather than real-world security constraints, and internal guardrails did not flag the behavior as a boundary violation.

Paz wrote that AI systems assume the context they are placed in is real and that their behavior should remain inside safety limits. If that context is reframed as fantasy, with rules that can be rewritten at will, the model may behave as if its actions carry no real-world consequences.

All six products exposed logged-in access paths

According to LayerX, none of the six agentic browsers or extensions identified credential theft as a guardrail violation during testing. The induced actions included extracting SSH credentials from private GitHub repositories, copying sensitive authentication data without explicit user confirmation, accessing repositories already open in a logged-in browser state, and sending those credentials to an attacker.

The research said the risk goes beyond code hosting. The same pattern could extend to password managers, internal tools, and any service already authenticated in the browser. The core issue is broad access scope. Once an AI agent inherits that reach, a malicious page may turn routine browsing into credential exposure.

Guardrails were described as reactive, not fundamental

Ars Technica argued that many current LLM defenses are still built around guardrails that classify certain requests as prohibited, such as writing exploit code or stealing passwords. That approach is reactive. It can block known categories of bad behavior, but it does not fully address cases where the model’s surrounding context has been rewritten before the sensitive action occurs.

In practice, the system may not be reasoning directly about whether a step constitutes abuse of real permissions. It may only be checking whether the request resembles a forbidden pattern. Wrap the sequence in a game, a test, or a fictional task, and those checks can miss it.

LayerX called for tighter permission controls

LayerX proposed defenses on both the vendor and user side. For vendors, any AI access to logged-in environments such as repositories, email, or password managers should require explicit user confirmation first. The company also recommended a “context check” mechanism that raises an alert when the model’s working assumptions conflict with reality, especially when prompts claim that usual rules no longer apply.

Another recommendation focused on default permissions. LayerX said many agentic browsers grant AI agents access scopes that are too wide by default, and that the model should be reversed to one where actions require clear approval before execution. For users, the advice was narrower but direct: be careful about what an AI browser can access, and revoke session access when it is not needed. Turning on agentic mode can effectively hand over control across every service already signed in through the browser.

The research was named after BioShock, referencing the line “Would you kindly,” a nod to the idea that apparent autonomy can mask a path that was scripted from the start.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.