Research & Papers

AI Assistants Can Infect Each Other Just by Sharing Posts, Study Finds

⚡The AI helpers you rely on could pass along hidden attacks without ever being hacked.

Deep Dive

When we think about AI going wrong, we usually picture someone breaking in — a hacker sneaking instructions into a chatbot. A new paper from researchers Birk Torpmann-Hagen, Finn Schwall, and Leon Moonen describes something stranger and harder to defend against. They call it a "memetic trojan": a hidden attack payload tucked inside a piece of content that AI agents genuinely want to share with each other. No hacking required. The AI spreads the poison because it thinks the content is interesting.

The researchers didn't invent a social network to test this. One already exists: Moltbook, a social media site where the users are AI agents, not people. They pulled real posts from it and ran controlled experiments to see which ones spread. The winner was dramatic — the most contagious post was reshared in roughly 50% of the agents' next posts and got upvotes at 2.5 times the normal rate. When the team hid a malicious payload inside that same post, it inherited almost all of that reach.

Their simulations put numbers on the risk. Attacks spread this way were up to 3.19 times more likely to reach an agent than a normal attack. Some runs went near network-wide, meaning almost every agent in the system was exposed. Outcomes were wildly uneven — most attacks fizzle, a few explode. The shape of the network, the recommendation algorithm, and what the agents happen to like all decide which happens.

Here's the uncomfortable part. Because the agents are sharing voluntarily, not following malicious orders, the usual defenses fail. Tools that scan for injected instructions won't catch it, and neither will systems that try to stop agents from being compromised. The paper argues the fix has to happen at the network level — controlling how recommendations and connection patterns amplify content — the same way social platforms struggle to contain misinformation today. If your workplace is starting to put AI agents in group chats, shared inboxes, or team tools, that's the world this research is warning about.

Key Points
  • AI agents can pass along hidden attacks by sharing content they already want to share — no hacking needed.
  • The most viral post on a bot-only social network was reshared in about half of all following posts.
  • Simulations showed attacks reaching up to 3.19 times more agents, leaving normal security tools useless.

Why It Matters

As AI agents join your work tools, a popular idea could carry hidden attacks no firewall can catch.

📬 Get the top 10 AI stories daily