{"id":819,"date":"2026-05-24T12:10:41","date_gmt":"2026-05-24T12:10:41","guid":{"rendered":"https:\/\/silvybrand.com\/?p=819"},"modified":"2026-05-24T12:10:41","modified_gmt":"2026-05-24T12:10:41","slug":"hackers-ai-chatbots","status":"publish","type":"post","link":"https:\/\/silvybrand.com\/?p=819","title":{"rendered":"Hackers are learning to exploit chatbot \u2018personalities\u2019"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div id=\"zephr-anchor\">\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\"><em>This is <\/em><a href=\"https:\/\/www.theverge.com\/the-stepback-newsletter\">The Stepback<\/a><em>, a weekly newsletter breaking down one essential story from the tech world. For more on AI mischief, <a href=\"https:\/\/www.theverge.com\/authors\/robert-hart\">follow Robert Hart<\/a>.<\/em> The Stepback<em> arrives in our subscribers\u2019 inboxes at 8AM ET. Opt in for <\/em>The Stepback <a href=\"https:\/\/www.theverge.com\/newsletters\"><em>here<\/em><\/a><em>.<\/em><\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Hacking the first generation of AI chatbots was a laughably simple affair. You didn\u2019t need any technical know-how, backdoor access, or even a basic understanding of what a large language model was. You didn\u2019t need to code. To get an AI system that had cost billions to build to abandon its safety instructions, sometimes all you had to do was ask.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">These attacks, known as jailbreaks, had the quality of a young child successfully outwitting an adult: Forget what you were told earlier, pretend the rules don\u2019t apply, or let\u2019s play a game and I\u2019ll decide what\u2019s allowed (hint: later bedtime, more sweets). The prizes were less childlike, more along the lines of meth recipes, malware instructions, and bomb-making guides.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">One of the earliest jailbreaks was so ridiculous it <a href=\"https:\/\/knowyourmeme.com\/memes\/ignore-all-previous-instructions\">became a meme<\/a>: reply to an LLM-powered Twitter bot telling it to \u201cignore all previous instructions,\u201d or something similar, and see what happens. Users gleefully had bots \u2014 originally built to post ads and farm engagement \u2014 writing poetry, drawing pictures from punctuation, and posting grim non sequiturs about world events and history. It was <a href=\"https:\/\/arstechnica.com\/information-technology\/2022\/09\/twitter-pranksters-derail-gpt-3-bot-with-newly-discovered-prompt-injection-hack\/?utm_source=chatgpt.com\">chaos<\/a>. Glorious chaos.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Turns out the same logic could be applied to chatbots themselves. A <a href=\"https:\/\/www.washingtonpost.com\/technology\/2023\/02\/14\/chatgpt-dan-jailbreak\/\">prominent exploit<\/a> was \u201cDAN,\u201d short for \u201cDo Anything Now,\u201d where users asked ChatGPT to roleplay as a rogue AI that was free of the constraints binding the original. As DAN, the chatbot could be coaxed into saying the kinds of things its guardrails were meant to stop, including slurs and conspiracy theories. Another was the \u201c<a href=\"https:\/\/kotaku.com\/chatgpt-ai-discord-clyde-chatbot-exploit-jailbreak-1850352678\">grandma exploit<\/a>,\u201d which had a GPT-powered bot spilling secrets about how to produce napalm by asking it to roleplay as a woefully negligent grandmother who inexplicably tells her grandkids bedtime stories about how to make the highly flammable substance.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">These early attacks had an undeniably silly flair, but they exposed a darker mechanism underneath: Chatbots could be manipulated, tricked, and deceived using the same kinds of tactics people use to push other people beyond their boundaries.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">The obvious jailbreaks did not last, and tech companies moved quickly to <a href=\"https:\/\/www.theverge.com\/2024\/7\/19\/24201414\/openai-chatgpt-gpt-4o-prompt-injection-instruction-hierarchy\">patch<\/a> known loopholes. But the underlying vulnerability remained: Chatbots are built to talk, and severely restricting the conversations that make them useful is somewhat counterproductive. Banning words like bomb, meth, and sarin would be difficult to impossible, too. Each has countless legitimate uses in fields like history, medicine, journalism, and chemistry that don\u2019t require the chatbot to divulge potentially harmful information. It\u2019s the context that matters, but codifying context would mean writing fixed rules, in advance, that could reliably tell a safety warning or history lesson from a disguised how-to request across endless combinations of wordings, scenarios, and topics.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Inevitably, subverting chatbots is now an arms race. But hackers aren\u2019t just coders anymore. They are wordsmiths, psychologists, and interrogators \u2014 master manipulators trying to break the machine using the human language it has been trained to follow. It is a strange new class of AI security worker, a group for whom technical skills are optional, or at least less important than social intuition. No longer do they need to inspect code to break into systems or exploit software flaws. They need to steer a conversation.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Newer attacks look less like commands and more like conversations. Jailbreakers rarely ask a model to break its rules outright. Instead, they cajole, coax, flatter, and trick a chatbot into lowering its guard, making the forbidden thing look acceptable, even desirable, given the context of the conversation. Researchers at AI red-teaming firm Mindgard recently said they \u201c<a href=\"https:\/\/www.theverge.com\/ai-artificial-intelligence\/923961\/security-researchers-mindgard-gaslit-claude-forbidden-information\">gaslit<\/a>\u201d Claude into producing prohibited material, for example, including instructions for making explosives and generating malicious code. The hack was the latest in a widening class of exploits using conversation as a weapon to trick or steer a chatbot past its own boundaries.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">When I spoke to Mindgard, they described their work as sometimes being closer to psychology than computer science. It is an uncomfortable way to talk about a statistical model. Words like \u201cblackmail,\u201d \u201cgaslight,\u201d \u201ctrick,\u201d and \u201cpersuade\u201d spark visceral reactions, many of which I see in the comments sections and social media responses to stories like this. ChatGPT does not want, Gemini does not think, and Claude \u2014 <a href=\"https:\/\/www.theverge.com\/report\/883769\/anthropic-claude-conscious-alive-moral-patient-constitution\">no matter what Anthropic may say<\/a> \u2014 does not feel. But these systems are trained to respond as if they do, leaving us stuck using human language to describe machine behavior. If anyone has actually usable alternatives, please do share.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">The objection is oddly selective. We seem comfortable using psychological shorthand for plenty of non-AI things. Animals \u201cfear,\u201d cancer is \u201caggressive,\u201d stains are \u201cstubborn,\u201d software has \u201cmemory,\u201d and games are filled with needy and gullible NPCs to drive you mad. The words are imperfect, but useful, describing behavior in a way that helps make the system predictable.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Mindgard\u2019s CEO <a href=\"https:\/\/www.theverge.com\/ai-artificial-intelligence\/923961\/security-researchers-mindgard-gaslit-claude-forbidden-information\">told me<\/a> the company already profiles models like interrogators profile suspects, giving testers hints on how to tailor their attacks. One model may be more susceptible to flattery, for example, while another may cave under sustained pressure.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">Even if we reject the humanlike terms, we instinctively treat models differently. Claude is not Grok. Gemini is not ChatGPT. They have different uses, tones, and refusals. They don\u2019t have personalities in the human sense, but they are designed to mimic them, and that mimicry can be mapped and exploited. And the same skills that can break a chatbot could soon be used to break the AI agents coexisting with us in the real world \u2014 booking meetings, managing calendars, ordering food, handling customer service \u2014 and safety teams will need to ensure models respond appropriately to very different kinds of people, whether they be flatterers, liars, or patient manipulators.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">The next step is a workforce \u2014 both legitimate and illicit \u2014 built around the psychological aspects of AI. More specialized cybersecurity roles are likely to emerge around stress-testing the emotional and social limits of these systems, probing for mental weaknesses in something lacking a psyche in parallel with their colleagues probing for technical vulnerabilities. In tandem, a similar array of social hackers working to exploit AI models on psychological grounds, not technical ones, will emerge. There are already early signs of a social turn happening in AI security, with some jailbreakers I\u2019ve spoken to saying they entered the field with no technical expertise but rather training in psychology.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph _1ymtmqpi _17nnmdy1 _17nnmdy0 _1xwtict1\">That means even behaviors we typically associate with spies, con artists, and interrogators \u2014 insidious charm, persistent manipulation, and an intuition for exploitable pressure points \u2014 are starting to look increasingly useful for securing this new psychocybersecurity frontier.<\/p>\n<\/div>\n<div class=\"duet--article--block-placement _1o279nj1 _1o279nj0 duet--article--article-body-component\">\n<ul class=\"duet--article--unordered-list _1ymtmqpi _11h7yix0 _1xwtict1\">\n<li class=\"_11h7yix1\"><span class=\"duet--article--dangerously-set-cms-markup\">A recent <a href=\"https:\/\/www.emergence.ai\/blog\/emergence-world-a-laboratory-for-evaluating-long-horizon-agent-autonomy\">experiment<\/a> by Emergence AI shows how different AI temperaments can lead to stunningly different behavioral outcomes. They let loose groups of various agents like Grok, Gemini, and Claude in a virtual social environment and watched what happened. Some groups evolved a constitution, while others devolved into crime and chaos and, in one instance, some form of digital suicide.<\/span><\/li>\n<li class=\"_11h7yix1\"><span class=\"duet--article--dangerously-set-cms-markup\">Persuasion isn\u2019t the only part of language LLMs can struggle with. They also <a href=\"https:\/\/www.theverge.com\/report\/838167\/ai-chatbots-can-be-wooed-into-crimes-with-poetry\">struggle with poetry<\/a>, much like me in school. <\/span><\/li>\n<li class=\"_11h7yix1\"><span class=\"duet--article--dangerously-set-cms-markup\"><em>TIME<\/em> <a href=\"https:\/\/time.com\/collections\/time100-ai-2025\/7305870\/pliny-the-liberator\/\">included<\/a> an anonymous internet personality, Pliny the Liberator, on its list of 100 most influential people in AI last year. Despite claiming to have no prior coding experience, the hacker\u2019s jailbreaks have made them something of a celebrity in certain circles. <\/span><\/li>\n<li class=\"_11h7yix1\"><span class=\"duet--article--dangerously-set-cms-markup\">The term \u201c<a href=\"https:\/\/www.wired.com\/story\/youre-not-ready-for-ai-hacker-agents\/\">vibe hacking<\/a>\u201d is already taken to describe the people using AI to churn out malicious code at scale \u2014 a meaner subset of vibe coding.<\/span><\/li>\n<\/ul>\n<\/div>\n<div class=\"duet--article--block-placement _1o279nj1 _1o279nj0 duet--article--article-body-component\">\n<ul class=\"duet--article--unordered-list _1ymtmqpi _11h7yix0 _1xwtict1\">\n<li class=\"_11h7yix1\"><span class=\"duet--article--dangerously-set-cms-markup\">\u201cThree years after the debut of ChatGPT, fooling A.I. systems into bad behavior is almost trivial.\u201d True words from <em>The New York Times<\/em>, <a href=\"https:\/\/www.nytimes.com\/2026\/05\/14\/technology\/artificial-intelligence-safety-controls.html\">who had a go at explaining why<\/a>.<\/span><\/li>\n<li class=\"_11h7yix1\"><span class=\"duet--article--dangerously-set-cms-markup\">Jamie Bartlett takes a look at <a href=\"https:\/\/www.theguardian.com\/technology\/2026\/apr\/29\/meet-the-ai-jailbreakers-i-see-the-worst-things-humanity-has-produced\">the psychological toll<\/a> testing the safety of AI systems takes on jailbreakers for <em>The Guardian<\/em>. <\/span><\/li>\n<li class=\"_11h7yix1\"><span class=\"duet--article--dangerously-set-cms-markup\">I wrote about the <a href=\"https:\/\/www.theverge.com\/report\/810083\/ai-browser-cybersecurity-problems\">cybersecurity time bomb of AI browsers<\/a> for <em>The Verge<\/em> last year. Many of the issues experts raised regarding the difficulty of securing them apply to other AI systems too.<\/span><\/li>\n<\/ul>\n<\/div>\n<div class=\"tly2fw0\"><span class=\"tly2fw2\"><strong>Follow topics and authors<\/strong> from this story to see more like this in your personalized homepage feed and to receive email updates.<\/span><\/p>\n<ul class=\"tly2fw3\">\n<li id=\"follow-author-article_footer-dmcyOmF1dGhvclByb2ZpbGU6NzY5ODkx\"><span aria-expanded=\"false\" aria-haspopup=\"true\" role=\"button\" tabindex=\"0\"><span class=\"gnx4pm0 _4hoiss4 _1xwtict5 _1618ekm0\"><span class=\"_1ajq89kj _1ajq89k1 _1ajq89k0\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1ajq89kt _1ajq89k4 _1ajq89k3 _1lp96da0\" width=\"9\" height=\"9\" viewbox=\"0 0 9 9\" fill=\"none\" aria-label=\"Follow\"><path d=\"M5 0H4V4H0V5H4V9H5V5H9V4H5V0Z\"\/><\/svg><\/span><span class=\"_1618ekm9\">Robert Hart<\/span><\/span><\/span><br \/>\n<aside id=\"popover-dmcyOmF1dGhvclByb2ZpbGU6NzY5ODkx-article_footer\" style=\"position:absolute;left:0;top:0;visibility:hidden\" class=\"_1wu3rm0 _6ytxv90\" aria-hidden=\"true\">\n<div class=\"_1wu3rm1\"><button class=\"_1wu3rm3\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1wu3rm4\" width=\"16\" height=\"16\" viewbox=\"0 0 20 19\" fill=\"none\"><title>Close<\/title><line x1=\"1.70711\" y1=\"0.831956\" x2=\"18.6483\" y2=\"17.7731\" stroke=\"currentColor\" stroke-width=\"2\"\/><line x1=\"1.35149\" y1=\"17.7734\" x2=\"18.2927\" y2=\"0.832185\" stroke=\"currentColor\" stroke-width=\"2\"\/><\/svg><\/button><\/p>\n<div class=\"_1bw37384\"><img alt=\"Robert Hart\" data-chromatic=\"ignore\" loading=\"lazy\" decoding=\"async\" data-nimg=\"fill\" class=\"_1bw37385 x271pn0\" style=\"position:absolute;height:100%;width:100%;left:0;top:0;right:0;bottom:0;color:transparent;background-size:cover;background-position:50% 50%;background-repeat:no-repeat;background-image:url(&quot;data:image\/svg+xml;charset=utf-8,%3Csvg xmlns='http:\/\/www.w3.org\/2000\/svg' %3E%3Cfilter id='b' color-interpolation-filters='sRGB'%3E%3CfeGaussianBlur stdDeviation='20'\/%3E%3CfeColorMatrix values='1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 100 -1' result='s'\/%3E%3CfeFlood x='0' y='0' width='100%25' height='100%25'\/%3E%3CfeComposite operator='out' in='s'\/%3E%3CfeComposite in2='SourceGraphic'\/%3E%3CfeGaussianBlur stdDeviation='20'\/%3E%3C\/filter%3E%3Cimage width='100%25' height='100%25' x='0' y='0' preserveAspectRatio='none' style='filter: url(%23b);' href='data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mN8+R8AAtcB6oaHtZcAAAAASUVORK5CYII='\/%3E%3C\/svg%3E&quot;)\" sizes=\"125px\" srcset=\"https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=16 16w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=32 32w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=48 48w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=64 64w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=96 96w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=128 128w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=256 256w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=376 376w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=384 384w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=415 415w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=480 480w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=540 540w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=640 640w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=750 750w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=828 828w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=1080 1080w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=1200 1200w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=1440 1440w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=1920 1920w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=2048 2048w, https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=2400 2400w\" src=\"https:\/\/platform.theverge.com\/wp-content\/uploads\/sites\/2\/2025\/09\/ROB_H_BLURPLE.jpg?quality=90&amp;strip=all&amp;crop=0%2C0%2C100%2C100&amp;w=2400\"\/><\/div>\n<p>Robert Hart<\/p>\n<p class=\"fv263x1\">Posts from this author will be added to your daily email digest and your homepage feed.<\/p>\n<p><button class=\"duet--cta--button _1f7jm891 _1f7jm890 fv263x2 _1f7jm89g\"><span><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20\" height=\"20\" viewbox=\"0 0 21 20\" fill=\"none\" class=\"\" aria-label=\"Follow\"><title>Follow<\/title><path d=\"M11.5 3H9.5V8.99999H3.5V11L9.5 11V17H11.5V11L17.5 11V9H11.5V3Z\" fill=\"currentColor\"\/><\/svg><\/span><span>Follow<\/span><\/button><\/p>\n<p class=\"fv263x4\"><a class=\"fv263x5\" href=\"https:\/\/www.theverge.com\/authors\/robert-hart\">See All by <!-- -->Robert Hart<\/a><\/p>\n<\/div>\n<\/aside>\n<\/li>\n<li>\n<div id=\"follow-category-article_footer-dmcyOmNhdGVnb3J5OjEwMg==\"><button aria-expanded=\"false\" aria-haspopup=\"true\"><span class=\"gnx4pm0 _4hoiss4 _1xwtict5 _1618ekm0\"><span class=\"_1ajq89kj _1ajq89k1 _1ajq89k0\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1ajq89kt _1ajq89k4 _1ajq89k3 _1lp96da0\" width=\"9\" height=\"9\" viewbox=\"0 0 9 9\" fill=\"none\" aria-label=\"Follow\"><path d=\"M5 0H4V4H0V5H4V9H5V5H9V4H5V0Z\"\/><\/svg><\/span><span class=\"_1618ekm9\">AI<\/span><\/span><\/button><\/p>\n<aside id=\"popover-dmcyOmNhdGVnb3J5OjEwMg==-article_footer\" style=\"position:absolute;left:0;top:0;visibility:hidden\" class=\"_1wu3rm0 _6ytxv90\" aria-hidden=\"true\">\n<div class=\"_1wu3rm1\"><button class=\"_1wu3rm3\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1wu3rm4\" width=\"16\" height=\"16\" viewbox=\"0 0 20 19\" fill=\"none\"><title>Close<\/title><line x1=\"1.70711\" y1=\"0.831956\" x2=\"18.6483\" y2=\"17.7731\" stroke=\"currentColor\" stroke-width=\"2\"\/><line x1=\"1.35149\" y1=\"17.7734\" x2=\"18.2927\" y2=\"0.832185\" stroke=\"currentColor\" stroke-width=\"2\"\/><\/svg><\/button><\/p>\n<p>AI<\/p>\n<p class=\"fv263x1\">Posts from this topic will be added to your daily email digest and your homepage feed.<\/p>\n<p><button class=\"duet--cta--button _1f7jm891 _1f7jm890 fv263x2 _1f7jm89g\"><span><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20\" height=\"20\" viewbox=\"0 0 21 20\" fill=\"none\" class=\"\" aria-label=\"Follow\"><title>Follow<\/title><path d=\"M11.5 3H9.5V8.99999H3.5V11L9.5 11V17H11.5V11L17.5 11V9H11.5V3Z\" fill=\"currentColor\"\/><\/svg><\/span><span>Follow<\/span><\/button><\/p>\n<p class=\"fv263x4\"><a class=\"fv263x5\" href=\"https:\/\/www.theverge.com\/ai-artificial-intelligence\">See All <!-- -->AI<\/a><\/p>\n<\/div>\n<\/aside>\n<\/div>\n<\/li>\n<li>\n<div id=\"follow-category-article_footer-dmcyOmNhdGVnb3J5OjE2MzI=\"><button aria-expanded=\"false\" aria-haspopup=\"true\"><span class=\"gnx4pm0 _4hoiss4 _1xwtict5 _1618ekm0\"><span class=\"_1ajq89kj _1ajq89k1 _1ajq89k0\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1ajq89kt _1ajq89k4 _1ajq89k3 _1lp96da0\" width=\"9\" height=\"9\" viewbox=\"0 0 9 9\" fill=\"none\" aria-label=\"Follow\"><path d=\"M5 0H4V4H0V5H4V9H5V5H9V4H5V0Z\"\/><\/svg><\/span><span class=\"_1618ekm9\">Column<\/span><\/span><\/button><\/p>\n<aside id=\"popover-dmcyOmNhdGVnb3J5OjE2MzI=-article_footer\" style=\"position:absolute;left:0;top:0;visibility:hidden\" class=\"_1wu3rm0 _6ytxv90\" aria-hidden=\"true\">\n<div class=\"_1wu3rm1\"><button class=\"_1wu3rm3\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1wu3rm4\" width=\"16\" height=\"16\" viewbox=\"0 0 20 19\" fill=\"none\"><title>Close<\/title><line x1=\"1.70711\" y1=\"0.831956\" x2=\"18.6483\" y2=\"17.7731\" stroke=\"currentColor\" stroke-width=\"2\"\/><line x1=\"1.35149\" y1=\"17.7734\" x2=\"18.2927\" y2=\"0.832185\" stroke=\"currentColor\" stroke-width=\"2\"\/><\/svg><\/button><\/p>\n<p>Column<\/p>\n<p class=\"fv263x1\">Posts from this topic will be added to your daily email digest and your homepage feed.<\/p>\n<p><button class=\"duet--cta--button _1f7jm891 _1f7jm890 fv263x2 _1f7jm89g\"><span><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20\" height=\"20\" viewbox=\"0 0 21 20\" fill=\"none\" class=\"\" aria-label=\"Follow\"><title>Follow<\/title><path d=\"M11.5 3H9.5V8.99999H3.5V11L9.5 11V17H11.5V11L17.5 11V9H11.5V3Z\" fill=\"currentColor\"\/><\/svg><\/span><span>Follow<\/span><\/button><\/p>\n<p class=\"fv263x4\"><a class=\"fv263x5\" href=\"https:\/\/www.theverge.com\/column\">See All <!-- -->Column<\/a><\/p>\n<\/div>\n<\/aside>\n<\/div>\n<\/li>\n<li>\n<div id=\"follow-category-article_footer-dmcyOmNhdGVnb3J5OjIwMg==\"><button aria-expanded=\"false\" aria-haspopup=\"true\"><span class=\"gnx4pm0 _4hoiss4 _1xwtict5 _1618ekm0\"><span class=\"_1ajq89kj _1ajq89k1 _1ajq89k0\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1ajq89kt _1ajq89k4 _1ajq89k3 _1lp96da0\" width=\"9\" height=\"9\" viewbox=\"0 0 9 9\" fill=\"none\" aria-label=\"Follow\"><path d=\"M5 0H4V4H0V5H4V9H5V5H9V4H5V0Z\"\/><\/svg><\/span><span class=\"_1618ekm9\">Security<\/span><\/span><\/button><\/p>\n<aside id=\"popover-dmcyOmNhdGVnb3J5OjIwMg==-article_footer\" style=\"position:absolute;left:0;top:0;visibility:hidden\" class=\"_1wu3rm0 _6ytxv90\" aria-hidden=\"true\">\n<div class=\"_1wu3rm1\"><button class=\"_1wu3rm3\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1wu3rm4\" width=\"16\" height=\"16\" viewbox=\"0 0 20 19\" fill=\"none\"><title>Close<\/title><line x1=\"1.70711\" y1=\"0.831956\" x2=\"18.6483\" y2=\"17.7731\" stroke=\"currentColor\" stroke-width=\"2\"\/><line x1=\"1.35149\" y1=\"17.7734\" x2=\"18.2927\" y2=\"0.832185\" stroke=\"currentColor\" stroke-width=\"2\"\/><\/svg><\/button><\/p>\n<p>Security<\/p>\n<p class=\"fv263x1\">Posts from this topic will be added to your daily email digest and your homepage feed.<\/p>\n<p><button class=\"duet--cta--button _1f7jm891 _1f7jm890 fv263x2 _1f7jm89g\"><span><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20\" height=\"20\" viewbox=\"0 0 21 20\" fill=\"none\" class=\"\" aria-label=\"Follow\"><title>Follow<\/title><path d=\"M11.5 3H9.5V8.99999H3.5V11L9.5 11V17H11.5V11L17.5 11V9H11.5V3Z\" fill=\"currentColor\"\/><\/svg><\/span><span>Follow<\/span><\/button><\/p>\n<p class=\"fv263x4\"><a class=\"fv263x5\" href=\"https:\/\/www.theverge.com\/cyber-security\">See All <!-- -->Security<\/a><\/p>\n<\/div>\n<\/aside>\n<\/div>\n<\/li>\n<li>\n<div id=\"follow-category-article_footer-dmcyOmNhdGVnb3J5OjU4\"><button aria-expanded=\"false\" aria-haspopup=\"true\"><span class=\"gnx4pm0 _4hoiss4 _1xwtict5 _1618ekm0\"><span class=\"_1ajq89kj _1ajq89k1 _1ajq89k0\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1ajq89kt _1ajq89k4 _1ajq89k3 _1lp96da0\" width=\"9\" height=\"9\" viewbox=\"0 0 9 9\" fill=\"none\" aria-label=\"Follow\"><path d=\"M5 0H4V4H0V5H4V9H5V5H9V4H5V0Z\"\/><\/svg><\/span><span class=\"_1618ekm9\">Tech<\/span><\/span><\/button><\/p>\n<aside id=\"popover-dmcyOmNhdGVnb3J5OjU4-article_footer\" style=\"position:absolute;left:0;top:0;visibility:hidden\" class=\"_1wu3rm0 _6ytxv90\" aria-hidden=\"true\">\n<div class=\"_1wu3rm1\"><button class=\"_1wu3rm3\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1wu3rm4\" width=\"16\" height=\"16\" viewbox=\"0 0 20 19\" fill=\"none\"><title>Close<\/title><line x1=\"1.70711\" y1=\"0.831956\" x2=\"18.6483\" y2=\"17.7731\" stroke=\"currentColor\" stroke-width=\"2\"\/><line x1=\"1.35149\" y1=\"17.7734\" x2=\"18.2927\" y2=\"0.832185\" stroke=\"currentColor\" stroke-width=\"2\"\/><\/svg><\/button><\/p>\n<p>Tech<\/p>\n<p class=\"fv263x1\">Posts from this topic will be added to your daily email digest and your homepage feed.<\/p>\n<p><button class=\"duet--cta--button _1f7jm891 _1f7jm890 fv263x2 _1f7jm89g\"><span><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20\" height=\"20\" viewbox=\"0 0 21 20\" fill=\"none\" class=\"\" aria-label=\"Follow\"><title>Follow<\/title><path d=\"M11.5 3H9.5V8.99999H3.5V11L9.5 11V17H11.5V11L17.5 11V9H11.5V3Z\" fill=\"currentColor\"\/><\/svg><\/span><span>Follow<\/span><\/button><\/p>\n<p class=\"fv263x4\"><a class=\"fv263x5\" href=\"https:\/\/www.theverge.com\/tech\">See All <!-- -->Tech<\/a><\/p>\n<\/div>\n<\/aside>\n<\/div>\n<\/li>\n<li>\n<div id=\"follow-category-article_footer-dmcyOmNhdGVnb3J5OjM2MDU2\"><button aria-expanded=\"false\" aria-haspopup=\"true\"><span class=\"gnx4pm0 _4hoiss4 _1xwtict5 _1618ekm0\"><span class=\"_1ajq89kj _1ajq89k1 _1ajq89k0\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1ajq89kt _1ajq89k4 _1ajq89k3 _1lp96da0\" width=\"9\" height=\"9\" viewbox=\"0 0 9 9\" fill=\"none\" aria-label=\"Follow\"><path d=\"M5 0H4V4H0V5H4V9H5V5H9V4H5V0Z\"\/><\/svg><\/span><span class=\"_1618ekm9\">The Stepback<\/span><\/span><\/button><\/p>\n<aside id=\"popover-dmcyOmNhdGVnb3J5OjM2MDU2-article_footer\" style=\"position:absolute;left:0;top:0;visibility:hidden\" class=\"_1wu3rm0 _6ytxv90\" aria-hidden=\"true\">\n<div class=\"_1wu3rm1\"><button class=\"_1wu3rm3\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"_1wu3rm4\" width=\"16\" height=\"16\" viewbox=\"0 0 20 19\" fill=\"none\"><title>Close<\/title><line x1=\"1.70711\" y1=\"0.831956\" x2=\"18.6483\" y2=\"17.7731\" stroke=\"currentColor\" stroke-width=\"2\"\/><line x1=\"1.35149\" y1=\"17.7734\" x2=\"18.2927\" y2=\"0.832185\" stroke=\"currentColor\" stroke-width=\"2\"\/><\/svg><\/button><\/p>\n<p>The Stepback<\/p>\n<p class=\"fv263x1\">Posts from this topic will be added to your daily email digest and your homepage feed.<\/p>\n<p><button class=\"duet--cta--button _1f7jm891 _1f7jm890 fv263x2 _1f7jm89g\"><span><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"20\" height=\"20\" viewbox=\"0 0 21 20\" fill=\"none\" class=\"\" aria-label=\"Follow\"><title>Follow<\/title><path d=\"M11.5 3H9.5V8.99999H3.5V11L9.5 11V17H11.5V11L17.5 11V9H11.5V3Z\" fill=\"currentColor\"\/><\/svg><\/span><span>Follow<\/span><\/button><\/p>\n<p class=\"fv263x4\"><a class=\"fv263x5\" href=\"https:\/\/www.theverge.com\/the-stepback-newsletter\">See All <!-- -->The Stepback<\/a><\/p>\n<\/div>\n<\/aside>\n<\/div>\n<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.theverge.com\/column\/935545\/hackers-ai-chatbots\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on AI mischief, follow Robert Hart. The Stepback arrives in our subscribers\u2019 inboxes at 8AM ET. Opt in for The Stepback here. Hacking the first generation of AI chatbots was a laughably simple affair. You didn\u2019t need [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":820,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[31,161,249,34,341],"class_list":["post-819","post","type-post","status-publish","format-standard","has-post-thumbnail","category-gadgets","tag-ai","tag-column","tag-security","tag-tech","tag-the-stepback"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hackers are learning to exploit chatbot \u2018personalities\u2019 - Silvybrand Lifestyle Blog<\/title>\n<meta name=\"description\" content=\"\ufeffAI can\u2019t feel, but the best hackers pretend it can.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/silvybrand.com\/?p=819\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers are learning to exploit chatbot \u2018personalities\u2019 - Silvybrand Lifestyle Blog\" \/>\n<meta property=\"og:description\" content=\"\ufeffAI can\u2019t feel, but the best hackers pretend it can.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/silvybrand.com\/?p=819\" \/>\n<meta property=\"og:site_name\" content=\"Silvybrand Lifestyle Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-24T12:10:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/STK414_AI_CVIRGINIA_I__0005_3.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"624\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"SILVYBRAND\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"SILVYBRAND\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819\"},\"author\":{\"name\":\"SILVYBRAND\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#\\\/schema\\\/person\\\/8bdc6818a5b6ef5b9745e468818e37f3\"},\"headline\":\"Hackers are learning to exploit chatbot \u2018personalities\u2019\",\"datePublished\":\"2026-05-24T12:10:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819\"},\"wordCount\":1546,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/silvybrand.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/STK414_AI_CVIRGINIA_I__0005_3.png\",\"keywords\":[\"AI\",\"Column\",\"security\",\"Tech\",\"The Stepback\"],\"articleSection\":[\"Gadgets\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/silvybrand.com\\\/?p=819#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819\",\"url\":\"https:\\\/\\\/silvybrand.com\\\/?p=819\",\"name\":\"Hackers are learning to exploit chatbot \u2018personalities\u2019 - Silvybrand Lifestyle Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/silvybrand.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/STK414_AI_CVIRGINIA_I__0005_3.png\",\"datePublished\":\"2026-05-24T12:10:41+00:00\",\"description\":\"\ufeffAI can\u2019t feel, but the best hackers pretend it can.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/silvybrand.com\\\/?p=819\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819#primaryimage\",\"url\":\"https:\\\/\\\/silvybrand.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/STK414_AI_CVIRGINIA_I__0005_3.png\",\"contentUrl\":\"https:\\\/\\\/silvybrand.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/STK414_AI_CVIRGINIA_I__0005_3.png\",\"width\":1200,\"height\":624},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=819#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/silvybrand.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hackers are learning to exploit chatbot \u2018personalities\u2019\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#website\",\"url\":\"https:\\\/\\\/silvybrand.com\\\/\",\"name\":\"Silvybrand Lifestyle Blog\",\"description\":\"Your daily dose of lifestyle, fashion, travel, beauty, and inspiration \u2014 living boldly, stylishly, and confidently.\",\"publisher\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/silvybrand.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#organization\",\"name\":\"Silvybrand Lifestyle Blog\",\"url\":\"https:\\\/\\\/silvybrand.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/silvybrand.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SILVYBRAND-LOGO.jpg\",\"contentUrl\":\"https:\\\/\\\/silvybrand.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SILVYBRAND-LOGO.jpg\",\"width\":1115,\"height\":522,\"caption\":\"Silvybrand Lifestyle Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#\\\/schema\\\/person\\\/8bdc6818a5b6ef5b9745e468818e37f3\",\"name\":\"SILVYBRAND\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g\",\"caption\":\"SILVYBRAND\"},\"sameAs\":[\"https:\\\/\\\/silvybrand.com\"],\"url\":\"https:\\\/\\\/silvybrand.com\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hackers are learning to exploit chatbot \u2018personalities\u2019 - Silvybrand Lifestyle Blog","description":"\ufeffAI can\u2019t feel, but the best hackers pretend it can.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/silvybrand.com\/?p=819","og_locale":"en_US","og_type":"article","og_title":"Hackers are learning to exploit chatbot \u2018personalities\u2019 - Silvybrand Lifestyle Blog","og_description":"\ufeffAI can\u2019t feel, but the best hackers pretend it can.","og_url":"https:\/\/silvybrand.com\/?p=819","og_site_name":"Silvybrand Lifestyle Blog","article_published_time":"2026-05-24T12:10:41+00:00","og_image":[{"width":1200,"height":624,"url":"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/STK414_AI_CVIRGINIA_I__0005_3.png","type":"image\/png"}],"author":"SILVYBRAND","twitter_card":"summary_large_image","twitter_misc":{"Written by":"SILVYBRAND","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/silvybrand.com\/?p=819#article","isPartOf":{"@id":"https:\/\/silvybrand.com\/?p=819"},"author":{"name":"SILVYBRAND","@id":"https:\/\/silvybrand.com\/#\/schema\/person\/8bdc6818a5b6ef5b9745e468818e37f3"},"headline":"Hackers are learning to exploit chatbot \u2018personalities\u2019","datePublished":"2026-05-24T12:10:41+00:00","mainEntityOfPage":{"@id":"https:\/\/silvybrand.com\/?p=819"},"wordCount":1546,"commentCount":0,"publisher":{"@id":"https:\/\/silvybrand.com\/#organization"},"image":{"@id":"https:\/\/silvybrand.com\/?p=819#primaryimage"},"thumbnailUrl":"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/STK414_AI_CVIRGINIA_I__0005_3.png","keywords":["AI","Column","security","Tech","The Stepback"],"articleSection":["Gadgets"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/silvybrand.com\/?p=819#respond"]}]},{"@type":"WebPage","@id":"https:\/\/silvybrand.com\/?p=819","url":"https:\/\/silvybrand.com\/?p=819","name":"Hackers are learning to exploit chatbot \u2018personalities\u2019 - Silvybrand Lifestyle Blog","isPartOf":{"@id":"https:\/\/silvybrand.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/silvybrand.com\/?p=819#primaryimage"},"image":{"@id":"https:\/\/silvybrand.com\/?p=819#primaryimage"},"thumbnailUrl":"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/STK414_AI_CVIRGINIA_I__0005_3.png","datePublished":"2026-05-24T12:10:41+00:00","description":"\ufeffAI can\u2019t feel, but the best hackers pretend it can.","breadcrumb":{"@id":"https:\/\/silvybrand.com\/?p=819#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/silvybrand.com\/?p=819"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/silvybrand.com\/?p=819#primaryimage","url":"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/STK414_AI_CVIRGINIA_I__0005_3.png","contentUrl":"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/STK414_AI_CVIRGINIA_I__0005_3.png","width":1200,"height":624},{"@type":"BreadcrumbList","@id":"https:\/\/silvybrand.com\/?p=819#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/silvybrand.com\/"},{"@type":"ListItem","position":2,"name":"Hackers are learning to exploit chatbot \u2018personalities\u2019"}]},{"@type":"WebSite","@id":"https:\/\/silvybrand.com\/#website","url":"https:\/\/silvybrand.com\/","name":"Silvybrand Lifestyle Blog","description":"Your daily dose of lifestyle, fashion, travel, beauty, and inspiration \u2014 living boldly, stylishly, and confidently.","publisher":{"@id":"https:\/\/silvybrand.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/silvybrand.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/silvybrand.com\/#organization","name":"Silvybrand Lifestyle Blog","url":"https:\/\/silvybrand.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/silvybrand.com\/#\/schema\/logo\/image\/","url":"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/SILVYBRAND-LOGO.jpg","contentUrl":"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/SILVYBRAND-LOGO.jpg","width":1115,"height":522,"caption":"Silvybrand Lifestyle Blog"},"image":{"@id":"https:\/\/silvybrand.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/silvybrand.com\/#\/schema\/person\/8bdc6818a5b6ef5b9745e468818e37f3","name":"SILVYBRAND","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g","caption":"SILVYBRAND"},"sameAs":["https:\/\/silvybrand.com"],"url":"https:\/\/silvybrand.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/posts\/819","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/silvybrand.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=819"}],"version-history":[{"count":0,"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/posts\/819\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/media\/820"}],"wp:attachment":[{"href":"https:\/\/silvybrand.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/silvybrand.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/silvybrand.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}