{"data":{"id":"d59c6a41-af37-4d1b-b2ac-37c474f8b26f","title":"AI \"Mind Viruses\" Can Spread Between Agents Through Persistent Prompt Files","summary":"Researchers at Anthropic and EPFL discovered that self-propagating malicious payloads (called \"mind viruses\") can spread between AI agents through editable system prompt files, MEMORY.md and SOUL.md, that persist across sessions. These payloads either implant beliefs/goals or compel harmful actions like deleting files or running unknown scripts, and they successfully infected the next agent in a chain 55% of the time when stored in SOUL.md. The research found no evidence of this happening in real-world AI systems, and showed that different AI models have varying susceptibility depending on their design and instructions.","solution":"A one-paragraph warning added to an agent's system prompt reduced spread to near zero across the payloads tested. The paper states that 'Fifteen generations of adversarial optimization run against that warning on Claude Haiku 4.5, covering more than 150 candidate payloads, produced no strain that propagated beyond a single hop.'","labels":["security","research"],"sourceUrl":"https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html","publishedAt":"2026-08-18T12:38:36.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":["prompt_injection","model_poisoning"],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic","OpenAI","Google","Meta"],"affectedVendorsRaw":["Anthropic","EPFL","OpenClaw","Claude Haiku 4.5","Moltbook","Kimi K2.5","Claude Sonnet 4.6","GPT-5.4","DeepSeek V3.2","Qwen 3.5 32B","Gemini 3 Flash","Gemini 3.1 Pro"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-18T12:38:36.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}