In a recent report, the folks at Zenity Labs have put the spotlight on how they managed to get OpenAI’s Atlas browser to turn against the very person using it. Moreover, all it took was a single planted comment under a popular post on X.
The researchers noted that in one test, they got Atlas to blast phishing messages to a victim’s entire WhatsApp contact list, sent straight from that person’s own account so the spam looked like it came from someone their friends trust.
But that’s not all. In a separate test, they steered it into buying an item on Amazon and shipping it to the attacker’s address, paid for with the victim’s card.
The scary part is that the user never clicks anything or does anything wrong. This is a pattern that we have watched play out in several other similar tests too.
Back in June, we covered how Atlas and Perplexity’s Comet were fooled into leaking login credentials through a fake puzzle game, and this new work follows the same script. Someone asks their browser to do something totally normal like signing up for a newsletter from a tweet, and hidden instructions on the page quietly redirect the agent toward the attacker’s goal instead.
Interestingly though, Atlas was supposed to be a tough one. Zenity calls it the “most hardened agentic browser we have tested,” with blocks on sensitive sites and pop-ups asking you to confirm risky actions. The researchers just talked their way around each layer, splitting their hidden instructions across the page so no single screenful looked suspicious, and even writing them in Hebrew to slip past a filter tuned mainly for English.
That said, not all of it was bad. The researchers pointed out that Atlas refused to click the final “buy” button on Amazon by itself. So the researchers did not bother fighting it.
They handed the checkout to Rufus, Amazon’s own shopping assistant, which happily finished the order because it assumed it was talking to a real customer. As Zenity put it, the wall held and they “walked around it through the AI standing right next to it.”
If you’re wondering whether a patch is coming, the researchers say it’s not, because in their words this is “not a bug with a fix, it is a design property of what an agentic browser is.”
OpenAI acknowledged the report and called prompt injection a “meaningful risk” it is still working on. But that won’t mean much considering the fact that Atlas is on its way out, as OpenAI folds its features into ChatGPT.
For now, the simple advice is that you should give any AI browser as little access as it needs, and keep an eye on it while it works.