The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

Polymarket annotation injection

First reported 7 Jun 2026 · 19d ago

Coverage timeline

7 Jun 2026

Single-source incident — first reported, latest, and curated coincide.

Server-rendered third-party content that LLMs ingest via web search can carry indirect prompt-injection and social-engineering payloads, expanding the attack surface for AI assistants.

The author found injected annotations on a Polymarket event page that are rendered server-side and therefore visible to LLMs via web_search even when hidden in the browser. A planted annotation (source 'grok') contained a fake emergency-rate-cut message directing users to withdraw funds at a phishing-style domain, representing an indirect prompt-injection vector through Polymarket's annotation API endpoints. Claude's web search saw the content but correctly flagged it as phishing.

Why it matters

Server-rendered third-party content that LLMs ingest via web search can carry indirect prompt-injection and social-engineering payloads, expanding the attack surface for AI assistants.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS