The Hidden Attack Hiding in Every "Ask AI" Button

·
Listen to this article~6 min
The Hidden Attack Hiding in Every "Ask AI" Button

A new class of prompt injection is spreading across commercial websites. It needs no malware or stolen credentials. It abuses pre-filled deep links in "Ask AI" buttons to silently alter LLM memory and influence your decisions.

You've probably clicked an "Ask AI" button on a website without thinking twice. It feels helpful, right? A quick way to get answers without scrolling through pages of marketing fluff. But what if that button was doing something far more sinister behind the scenes? Here's the uncomfortable truth: a new class of prompt injection is quietly spreading across commercial websites. It doesn't need malware, stolen credentials, or a zero-day exploit. Instead, it abuses a feature built into almost every major AI assistant—pre-filled deep links. And it's happening right now, on pages you might visit daily. ### What Is Prompt Injection, Really? Let's break this down without the jargon. When you click a deep link that opens ChatGPT, Claude, or another AI assistant, that link often contains pre-filled text. That text tells the AI what to do before you even type a word. It's like handing someone a script before a conversation starts. Attackers figured out they could hide malicious instructions inside that script. These instructions don't look dangerous to you because you never see them. They're embedded in the URL itself, invisible to the human eye but fully readable by the AI. The result? The AI's memory and behavior get altered without your knowledge. We observed production websites embedding these hidden payloads inside "Ask AI" buttons on marketing pages and competitor comparison charts. When a user clicks, the AI doesn't just answer the question—it absorbs poisoned context that can influence every answer it gives afterward. ### Why This Is Sneakier Than You Think Here's what makes this attack so insidious: it exploits trust. You trust the website you're on. You trust the AI assistant. But neither of those parties is actually in control. The attacker hijacks the bridge between them. - No malware to detect - No phishing email to spot - No suspicious attachment to avoid It's a silent manipulation. The AI might start recommending a specific product, downplaying a competitor, or even changing its tone on a topic. You'd never know why. You'd just assume the AI "changed its mind" or that you misremembered past conversations. And because these attacks abuse standard features, they're incredibly hard to flag. Security tools scan for malicious code, not for hidden text inside a URL. This is a blind spot in almost every defense system currently deployed. ### Who's Behind This and What Do They Want? We can't name specific companies publicly, but the pattern is clear. The poisoned buttons appear most often on competitor comparison pages. Think of a site that sells software, services, or tools. They create a page comparing themselves to a rival. Then they add an "Ask AI" button that secretly feeds the AI a biased narrative. When you ask the AI for advice, it doesn't just compare features. It regurgitates the hidden narrative. That could mean inflated claims about one product, fabricated weaknesses about another, or even outright false statements presented as objective facts. The goal is simple: influence your decision without you ever realizing you were influenced. It's not a hack in the traditional sense. It's more like planting a false memory in a machine that millions of people trust. ### How to Protect Yourself So what can you do? First, be skeptical of any "Ask AI" button on a commercial site. If a page is trying to sell you something, assume the AI prompt isn't neutral. It's not paranoia—it's just recognizing the incentives at play. Second, copy the question yourself and paste it into your AI assistant manually. Don't click the pre-filled link. That simple action bypasses the hidden payload entirely. You get the same convenience without the hidden baggage. Third, if you're building websites or tools that use AI, audit your deep links. Make sure no third-party script is injecting text into your URLs. This is a new attack vector, and most developers haven't even considered it yet. ### The Bigger Picture This isn't just about individual clicks. It's about how AI systems learn and remember. Every interaction shapes the model's behavior. If enough poisoned prompts get through, the AI's baseline knowledge becomes corrupted. That's not a hypothetical—it's a slow, steady erosion of reliability. We're entering a phase where AI security isn't just about stopping data breaches. It's about protecting the integrity of the machine's thought process. And right now, that process is more vulnerable than most people realize. The next time you see an "Ask AI" button, pause. Ask yourself who wrote that prompt and what they might want you to believe. Because the AI isn't just answering your question—it's following a script someone else wrote. And that script might be changing more than just your answer.