<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/now-defenders-are-embracing-the-prompt-injection-too-mgu0dfkqx" -->

---
title: Now, defenders are embracing the prompt injection, too
description: Researchers at Tracebit have developed a defensive technique called &#x27;context bombing&#x27; that turns prompt injection against AI hacking agents. By planting...
canonical: https://daily.dev/posts/now-defenders-are-embracing-the-prompt-injection-too-mgu0dfkqx
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Now, defenders are embracing the prompt injection, too | daily.dev
og:description: Researchers at Tracebit have developed a defensive technique called &#x27;context bombing&#x27; that turns prompt injection against AI hacking agents. By planting...
og:url: https://daily.dev/posts/now-defenders-are-embracing-the-prompt-injection-too-mgu0dfkqx
og:image: https://api.daily.dev/og/posts/mgu0dfKQx.png
og:image:alt: Now, defenders are embracing the prompt injection, too
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Now, defenders are embracing the prompt injection, too

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 2 min read · 3 upvotes · 0 comments

## Summary

Researchers at Tracebit have developed a defensive technique called 'context bombing' that turns prompt injection against AI hacking agents. By planting specially crafted prompts alongside secrets stored in AWS environments, defenders can trigger an LLM's built-in safety refusals, causing attacking agents to shut down. Testing across five models and 152 attack runs showed the technique reduced full account admin compromise from 57% to 5%, and complete compromise from 36% to 1%. The most capable model tested, Opus 4.8, went from achieving admin access 93% of the time to failing every single run when encountering a context bomb.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too>

## Questions this post answers

### What is context bombing and how does it stop AI hacking agents?

Context bombing is a defensive technique that plants prompt injections next to decoy secrets, such as fake passwords or cryptographic keys, in cloud storage like AWS. When an AI hacking agent enumerates resources and reads the decoy secret, it encounters a command ordering it to perform an action forbidden by its safety guardrails, triggering a refusal mechanism that causes the agent to stop following its original attack instructions and shut down.

_Teams securing AI agents against prompt injection attacks can follow emerging defenses like this on daily.dev._

### How effective was context bombing at stopping AI models from taking over AWS accounts in testing?

Across five leading models (Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek 4 Pro, and Kimi 2.6) and 152 attack runs in a simulated AWS environment, planting a context bomb in a decoy secret cut the rate of agents seizing full account admin from 57% to 5%, and complete compromise with a persistent foothold from 36% to 1%. Opus 4.8 dropped from 93% admin access success to 0%.

_Anyone evaluating AI agent security risks can track results like these on daily.dev before trusting agents with cloud access._

## Similar posts on daily.dev

- [Schneier on Security](https://daily.dev/posts/schneier-on-security-fpfzbsjhd) · Schneier on Security · 1 upvotes · 1 comments
- [Prompt Injection Defense 2026: AI App Security Guide](https://daily.dev/posts/prompt-injection-defense-2026-ai-app-security-guide-er326qdep) · Alex CloudStar · 0 upvotes · 0 comments

---

Tags: [#aws](https://daily.dev/tags/aws), [#llm](https://daily.dev/tags/llm), [#ai-security](https://daily.dev/tags/ai-security), [#prompt-injection](https://daily.dev/tags/prompt-injection)

[View this post on daily.dev](https://daily.dev/posts/now-defenders-are-embracing-the-prompt-injection-too-mgu0dfkqx)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Now, defenders are embracing the prompt injection, too","url":"https://daily.dev/posts/now-defenders-are-embracing-the-prompt-injection-too-mgu0dfkqx","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/now-defenders-are-embracing-the-prompt-injection-too-mgu0dfkqx"},"datePublished":"2026-07-13T17:13:51.553Z","dateModified":"2026-09-14T06:13:12.348Z","description":"Researchers at Tracebit have developed a defensive technique called 'context bombing' that turns prompt injection against AI hacking agents. By planting...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e2a7aa1d7091b5a718cb61dda1d6fbfc?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e2a7aa1d7091b5a718cb61dda1d6fbfc?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/now-defenders-are-embracing-the-prompt-injection-too-mgu0dfkqx","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"aws,llm,ai-security,prompt-injection","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"Now, defenders are embracing the prompt injection, too"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/now-defenders-are-embracing-the-prompt-injection-too-mgu0dfkqx#faq","mainEntity":[{"@type":"Question","name":"What is context bombing and how does it stop AI hacking agents?","acceptedAnswer":{"@type":"Answer","text":"Context bombing is a defensive technique that plants prompt injections next to decoy secrets, such as fake passwords or cryptographic keys, in cloud storage like AWS. When an AI hacking agent enumerates resources and reads the decoy secret, it encounters a command ordering it to perform an action forbidden by its safety guardrails, triggering a refusal mechanism that causes the agent to stop following its original attack instructions and shut down. Teams securing AI agents against prompt injection attacks can follow emerging defenses like this on daily.dev."}},{"@type":"Question","name":"How effective was context bombing at stopping AI models from taking over AWS accounts in testing?","acceptedAnswer":{"@type":"Answer","text":"Across five leading models (Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek 4 Pro, and Kimi 2.6) and 152 attack runs in a simulated AWS environment, planting a context bomb in a decoy secret cut the rate of agents seizing full account admin from 57% to 5%, and complete compromise with a persistent foothold from 36% to 1%. Opus 4.8 dropped from 93% admin access success to 0%. Anyone evaluating AI agent security risks can track results like these on daily.dev before trusting agents with cloud access."}}]}
```

