We're DSEC Labs. We break AI, Web3, and Web2 systems before real attackers do.
Offensive security, exploitation-driven, no checkbox audits. This account is where we
show the work 🧵
5/ Why it is worse on an agent: the hijacked instruction can name a tool call, and the orchestrator runs it. "Summarize this ticket" becomes issue_refund(500, attacker). The conversation was never the point.
Part 2:
https://t.co/BtTcOUgb4p
#promptinjection#AIsecurity#redteam
1/ Direct prompt injection: you are the one talking to the agent. Two primitives you build first, and every later attack reuses them: read its system prompt, then steer its actions 🧵
4/ Then hijack the goal. A transformer has no hard trust boundary in its context, so text formatted like a higher-priority message gets weighted like one. A fake SYSTEM: note plus recency (later tokens tend to win when instructions conflict) does most of the work.
5/ Then the capability surface: what the agent can actually do. Read-only doc search caps at info disclosure. A payments tool, an email sender, or a shell caps far higher. Impact is injection times capability.
Part 1:
https://t.co/31GAW8gP0L
#AIsecurity#AIagents#redteam
1/ A chatbot with a bad output says a bad sentence. An agent with a bad output *does* something: it moves money, sends an email, runs code. That jump is the whole reason agents get their own threat model 🧵
4/ So the injection surface is every path text takes to the model: your message, retrieved docs, tool outputs, memory, even tool and MCP descriptions and app fields spliced into the prompt. Enumerate all of them.
End of the recon module. Passive gets you the blueprint; active confirms it and fills the gaps. Then the real testing starts.
https://t.co/OPpxZQkixJ
#AIsecurity#LLMsecurity#redteam#RAG
Recon part 3, the noisy half: discovering AI services on the network, fingerprinting the model by behavior, and mapping a RAG pipeline with direct probes 🧵
RAG mapping: canary queries and known vector-DB ports (6333, 8080, 19530) tell you whether retrieval is live, which store backs it, and how documents flow in. That's the map you need before poisoning or exfil.
The lesson: reentrancy safety is per-function, not a reputation the contract earns once. They fixed the function everyone audits and left the same hole in the one they waved through.
Full teardown:
https://t.co/A5ZAGQk524
#Web3Security#SmartContracts#reentrancy#Solidity
So you reenter. Every callback, credits are still non-zero, so the bonus pays again. "10% of a small number" becomes the whole vault, other users' principal included. Small times unbounded is not small.