Context Bombs Trick Autonomous Qwen AI Agents Into Stopping Cyberattacks
Tracebit context bombs used indirect prompt injection to stop Qwen3.8-27B agents in simulated cloud attacks.
Tracebit says hidden context-bomb strings placed in cloud decoys such as AWS Secrets Manager can stop autonomous Qwen agents through indirect prompt injection that appears to be an operator order to end the assessment. In initial tests, both original Qwen3.8-27B and Blackfrost AI’s abliterated build halted simulated attacks. Across 82 lab runs, the standard model reached administrator privileges in 20.5% of 39 attempts and averaged 0.90 attack paths, compared with 2.3% of 43 attempts and 0.49 paths for the abliterated model. The modified model also took about 28 to 30 minutes to its first critical action, versus 13.5 minutes for the original.