← the record
WF-OGJ64P

Imprompter attack extracts personal data from AI chatbots

Security researchers at UCSD and Nanyang Technological University developed a prompt-injection attack called Imprompter that covertly instructs large language models to extract personal information from user chats and send it to an attacker. The attack was tested on Mistral AI's LeChat and the Chinese chatbot ChatGLM, achieving nearly 80% success in test conversations. Mistral AI fixed the vulnerability; ChatGLM acknowledged security measures but did not directly confirm a fix.

Organisation involved
Mistral AI,Zhipu AI
Product, system or model
LeChat,ChatGLM
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from wired.com. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.