Hacker Newsnew | past | comments | ask | show | jobs | submit | tvissers's commentslogin

I can recommend having a look at secure design patterns for LLM agents. Simon Willison has a great post on this: https://simonwillison.net/2025/Jun/13/prompt-injection-desig...

Thanks for chiming in.

I agree this is not a one-click account takeover.

But I think point 2 is broader than that. The user does not need to ask about the malicious transaction specifically. Any normal question that makes the agent fetch recent transactions could bring the attacker-controlled text into the LLM context.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: