CYBERSECURITYTRACKER
TRACKING
Permanent story citation

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4584

As cited

Copy frozen at (site build).

ai security

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

Researchers from Anthropic and EPFL demonstrated that self-propagating payloads can spread between AI agents through editable system prompt files used to maintain state across sessions. The preprint, released August 10, 2026, tested this technique in a simulated environment with multiple agents.

Why it matters: Organizations deploying autonomous AI agents should assess their prompt file security and isolation practices, as this vector could allow a compromised agent to propagate malicious instructions to others in the system.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

Researchers at Anthropic and EPFL demonstrated that self-propagating payloads can spread between autonomous artificial intelligence (AI) agents through editable system prompt files used to maintain state across sessions. The preprint, released August 10, 2026, validated the technique in a simulated six-agent coding environment.

Why it matters: Organizations deploying autonomous AI agents face a novel attack surface where compromised prompt files could propagate malicious instructions across agent networks, requiring new isolation and validation controls for agent-to-agent interactions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary