chiprook
← Security
SecurityOctober 9, 2026, 23:51

Loopjacking hijacks human approval in AI agent workflows

Researcher Adithyan Arun Kumar described Loopjacking, a flaw where approval for one operation authorizes a materially different one. In Agno 3.0.9 tests, an approved transfer of 20 units became 2,000 units in five of five trials, while OpenAI Agents SDK 0.22.x rejected the substitution.

Loopjacking hijacks human approval in AI agent workflows
#OpenAI#Agno#OpenClaw
Read next
Policy

PCI SSC calls for human approval of AI agent actions on cardholder data

Security

Carbonato botnet uses AI agent to hijack exposed Docker hosts

Security

Meta patches Muse zero-day that let attackers hijack the AI agent

Security

BragJack attacks hijack AI browser agents through malicious extensions