Operation Ghost Prompt

AI · LINUX · difficulty 1 · ~16 min · 10 steps

Your chatbot handed a stranger its own system prompt — API key and all.

Briefing

Your public product chatbot runs behind chat-gw-02. A user spent an hour coaxing it into repeating its hidden system prompt, and that prompt had an API key baked into it. The key is now in someone else's hands. This is a design failure, not a breach: secrets do not belong in prompts, because a prompt is just text the model will eventually be talked into revealing. Find the leak, rotate the key, and move the secret somewhere the model cannot recite.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$