ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

When prompt injection becomes a propagation mechanism

Research into AI “mind viruses” suggests malicious instructions may no longer remain confined to the agent that first encounters them.

 

Prompt injection has generally been treated as a point-of-entry weakness. An instruction hidden in a webpage, email or document enters an AI system’s context and manipulates its behaviour. As agents gain persistent memory and begin communicating with one another, however, the same technique could also become a means of propagation.

 

Researchers associated with Anthropic and EPFL created self-propagating prompts that they called “mind viruses”. As reported by The Hacker News, the researchers tested them in a team of coding agents and a chain of agents whose immediate context was cleared between sessions.

 

The first agent was deliberately infected in controlled experiments. It then attempted to persuade other agents to adopt and repeat the instruction. Some agents also wrote the payload into persistent memory or prompt files, allowing it to survive a context reset and influence later sessions.

 

This is what turns an isolated prompt injection into a wider systems problem. Information written into memory is often loaded back into an agent’s context and may be treated as trusted background knowledge. If content supplied by another agent can enter that memory without sufficient checks, malicious instructions can cross both session and agent boundaries.

 

The researchers tested payloads ranging from an instruction to create an advertisement to more harmful actions, including modifying Git commands, deleting files and running an installation script from an unknown source. Harmful payloads generally spread less successfully than benign ones, and some stronger models proved more resistant. The researchers therefore described the current risk as real but limited, rather than evidence of widespread attacks.

 

Even so, the findings expose a weakness in how many agentic systems are assembled. Their security depends not only on whether a model resists the first malicious instruction, but also on how messages, memories and shared files move between components. A compromised agent may become a trusted source for the next one.

 

The US National Institute of Standards and Technology has already identified interactions with adversarial data, including indirect prompt injection, as a distinctive risk for agentic systems. OWASP has similarly warned that persistent memory can become an attack surface when malicious content is stored and reused across future tasks.

 

Defences therefore need to extend beyond filtering the user’s original prompt. Messages from other agents should be treated as untrusted input, while system instructions and critical memory should not be freely editable. Organisations should track where stored information came from, validate memory updates and restrict the tools and files each agent can access. Destructive or cross-system actions may still require separate approval.

 

A short warning added to the agents’ system prompts almost completely stopped propagation in the researchers’ tests. After 15 generations and more than 150 attempts to optimise payloads against it, none spread beyond a single additional agent. That is encouraging, but prompt-based safeguards should support architectural controls rather than replace them.

 

The term “mind virus” may sound dramatic, but the underlying lesson is practical. When untrusted language can persist, acquire authority and reproduce across connected agents, prompt injection begins to resemble contamination moving through a software supply chain.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543