HNHacker News
TopNewBestAskShowJobs

tvissers

81 karma · joined March 26, 2021

submissionscomments
tvissers··on A €0.01 bank transfer could compromise a banking AI agent
I can recommend having a look at secure design patterns for LLM agents. Simon Willison has a great post on this: https://simonwillison.net/2025/Jun/13/prompt-injection-desig...
tvissers··on A €0.01 bank transfer could compromise a banking AI agent
Thanks for chiming in.

I agree this is not a one-click account takeover.

But I think point 2 is broader than that. The user does not need to ask about the malicious transaction specifically. Any normal question that makes the agent fetch recent transactions could bring the attacker-controlled text into the LLM context.