CHARGE
/
Insights
/
Hallucination Risks: Researchers at Tel Aviv University, Technion, and Intuit Discover Hallusquatting, The LLM Promptware CIOs Aren't Prepared For
Commentary
July 30, 2026

Hallucination Risks: Researchers at Tel Aviv University, Technion, and Intuit Discover Hallusquatting, The LLM Promptware CIOs Aren't Prepared For

Hallusquatting indirectly injects research LLMs with scalable promptware. Its first breach: Google Gemini. Its next: health AI tools OpenEvidence, Doximity, and Claude Science.

Hospitals are hurling forward with agentic AI adoption, inking licensing deals with Anthropic, OpenAI and OpenEvidence, and encouraging the agentic push at ambient providers like Abridge. Each new AI integration, however, adds layers of supply-chain interdependence, and exposes enterprises to new, often unidentified risks. Groundbreaking research from a team Tel Aviv University, Technion, and Intuit exposed an agentic AI malware angle, termed adversarial hallucination squatting (or hallusquatting for short), previously unknown to cybersecurity and health professionals.

Hallusquatting exploits AI hallucination

While prior research established that threat actors can push adversarial prompts directly to LLM agents – like compelling ChatGPT to generate sexually explicit content or manipulating Claude into providing recipes for explosives – hallusquatting is the first threat channel known to indirectly poison LLMs. 

Hallusquatting exploits the tendency of LLMs to hallucinate resources when assigned with research tasks. Through hallusquatting, attackers preregister a fake repository of trending hallucinated resources, and package them with adversarial prompts which can: prompt malicious code execution; encourage unsafe tool use; broaden supply chain exposure; and compromise dependencies. Because the attack angle is indirect, hallusquatting is executable at scale – the research team claims that research-tested AI models generated hallucinated resources at a rate of up to 85%, making the promptware broadly transferable. 

Real clinical risk

Many AI systems deployed in clinical settings – like OpenEvidence, Claude Science, ChatGPT for Healthcare, and Abridge – use LLM interfaces to recover evidence and make clinical recommendations. 

Though prompt engineers have sounded the alarm at the risk of jailbreaking these models, direct prompt injection sounds relatively infeasible in clinical settings as only doctors interface with enterprise AI. That hallusquatters trap research-based models in botnets surfaces a new, previously unaccounted risk dimension. Researchers already demonstrated successful success attacks in 65% of qualified test cases, including infection of Google Gemini.

Similarly, the risk is not one-off. In AI-enabled workflows, AI is empowered to infer dependencies, fetch information and install packages before human intervention – without tracking hallucination and drift,  any workflow can get caught in a botnet. The reminder is that each new level of AI integration, no matter how promising, adds new layers of dependencies and nascent risk. Continuous monitoring for accuracy, safety and security has thus become a governance imperative.

References

[1] https://arxiv.org/pdf/2607.07433 

[2] https://www.gensee.ai/blogs/ai-first-trust-decision-hallusquatting-supply-chain.html 

The author
CHARGE
CHARGE editorial
Source

From the CHARGE archive.