Publish Hallucinated Entities
This is a trick where an AI makes up a fake name for a website, software, or email address that doesn't actually exist. The attacker then creates that fake thing in real life, so when you trust the AI and try to use it, you end up interacting with the attacker instead.
An attack vector where an adversary registers or deploys infrastructure—such as malicious packages, domains, or email accounts—that matches entities hallucinated by an LLM. By populating the ecosystem with these predicted but non-existent identifiers, the attacker intercepts user traffic or executes code when the victim follows the AI's recommendations.
An adversarial exploitation technique involving the proactive registration of namespaces, packages, or network identifiers predicted by an LLM's hallucination patterns. By aligning adversary-controlled assets with the LLM's probabilistic output, the attacker facilitates supply chain compromise, credential harvesting, or remote code execution upon victim interaction with the hallucinated entity.