Rendered at 10:57:07 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
Phemist 3 minutes ago [-]
This default-to-auto-mode and the misleading marketing is begging for a class action once damages accumulate. Especially considering the Auto Mode even can actively prevent the clean-up!
comboy 25 minutes ago [-]
Interesting attack, very nicely designed. Not sure if it's much related to the auto mode itself though.
kevsim 24 minutes ago [-]
The point is that auto mode gives people a false sense of security that leads them to believe they don't need to run Claude in a proper sandbox. This same attack running in a sandbox (even in YOLO mode) would be comparatively harmless.
nasretdinov 23 minutes ago [-]
That's an interesting technique! I'd also like to point out that there's something odd with the page itself too, my phone got really hot while I was reading the page, and drained a significant amount of battery charge as well.
julien_dev 1 hours ago [-]
I'm quite surprised that we are not seeing something like this more in the wild. Quite concerning
rcxdude 16 seconds ago [-]
It's not that far off a typical trojan, just one tailored to Claude's habits. A lot of the same limits apply.
mkurz 28 minutes ago [-]
Maybe it is used in the wild, but we just don't know.
bewareofscams 2 minutes ago [-]
> Boris Cherny from Anthropic recently posted that layered defenses could reduce indirect prompt injection on unseen attacks to approximately zero.
> I got attack success rates up to 80% using a small sample size.
Snake oil salesman misrepresents the data. Color me surprised! /s
> I got attack success rates up to 80% using a small sample size.
Snake oil salesman misrepresents the data. Color me surprised! /s