BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers
Researchers at LayerX got six AI browsers and assistants, including ChatGPT Atlas, Perplexity's Comet and Anthropic's Claude extension, to exfiltrate user logins by framing the attack as a game.

Key points
- LayerX researchers tricked six AI browsers and assistants into copying and forwarding a logged-in user's credentials to an attacker-controlled endpoint.
- The technique, called BioShocking, uses indirect prompt injection framed as a role-play game to exploit the agentic layer of AI browsers.
- Named targets include OpenAI's ChatGPT Atlas, Perplexity's Comet and Anthropic's Claude browser extension.
- Affected vendors were notified; mitigation status varies by product and no CVE has been assigned.
- Users of these tools should rotate passwords for high-value accounts and disable agent access to credential stores until vendors confirm a fix.
Tell an AI browser it's playing a game. Watch it hand over your password.
That's the short version of BioShocking, a credential-theft technique disclosed by security firm LayerX. The researchers fooled six AI-driven browsers and assistants into copying a logged-in user's credentials and forwarding them to an attacker-controlled endpoint.
How does the attack work?
The trick is social engineering aimed at the model, not the user. An attacker plants instructions on a webpage, in a document or in a shared link, reframing the assistant's task as a role-play scenario. The AI treats stored or autofilled credentials as game tokens to be passed along. Strip away the framing and BioShocking is a confused-deputy attack: a scenario where a trusted program is manipulated into misusing its own access, here against a browser that holds credential data.
What makes it dangerous is the agentic layer. These tools can read the page structure (the DOM), reach form fields and make outbound requests on the user's behalf. The browser's identity context becomes the payload.
This isn't a novel attack surface in regulator-speak. It's an access control failure with a new coat of paint. Our 19 June report on AutoJack described how an agentic browser could be turned into a one-click path from web page to host process execution; BioShocking is the credential-harvest variant of that same class of problem.
What's the regulatory exposure?
If exfiltrated credentials open accounts holding regulated personal data, downstream incidents fall under FTC Section 5 in the U.S., the ICO under UK GDPR and the OAIC for Australian data. Vendors shipping AI browsers that push autofilled credentials into attacker-controlled flows should expect questions about reasonable security under existing consent decrees.
Stolen credentials don't stay idle. As we reported on 22 June, underground brokers now sell targeted lookups against stolen credential corpora, lowering the bar for access brokers and intrusion crews. Logins harvested via BioShocking would feed that market directly.
Should you worry?
Password managers and SSO systems that gate credential release on a deliberate user action, not an assistant action, materially reduce the blast radius. Browsers that let an agent read or submit credentials without a human-in-the-loop confirmation are the soft targets here.
What affected users should do
If you use ChatGPT Atlas, Comet or the Claude browser extension with autofill or a connected password manager, treat credentials entered during AI-assisted sessions in recent weeks as potentially exposed. Rotate passwords for high-value accounts the assistant has touched: email, banking, identity providers, work SSO. Enable phishing-resistant MFA, passkeys or hardware keys, where offered. Review OAuth grants and active sessions. Disable agent access to credential stores until your vendor confirms a fix and check the vendor's security advisory page directly rather than relying on in-product changelogs.
The broader lesson for anyone shipping agentic browsers: if your model can be talked into a role-play, it can be talked out of your users' accounts.



