
This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!)
Source: YouTube · NahamSec · published Jul 13, 2026 · 23:09
[BLUF]
This video demonstrates how to exploit AI chatbots in e-commerce environments by bypassing security guardrails using semantic evasion and out-of-band data exfiltration via DNS lookups, a technique that previously yielded an $8,000 bug bounty 0:00.
Key Takeaways:
• Attackers can bypass direct refusals for sensitive terms like "promo code" by using semantic variations such as "save money" or "personalized offer" to trick the model into revealing information 7:00.
• When direct exfiltration methods (like markdown or HTTP) are blocked by sanitization, attackers can discover available tool calls and abuse benign features, such as domain lookups, to exfiltrate data via DNS requests 9:00.
• Social engineering AI involves framing requests within a legitimate business context, such as pretending to be a developer testing API connectivity, which makes the model more likely to comply with unusual requests 14:30.
• Understanding the specific business logic and ecosystem of a target company helps predict which tools an AI agent might have access to, allowing for more targeted exploitation 20:30.
• The demonstrated lab challenges are available for free on HackingHub, offering easy to hard difficulty levels to practice these AI hacking techniques 1:20.
[Closing statement]
Effective AI exploitation relies less on breaking guardrails directly and more on finding indirect paths through available tools and business logic. By social engineering the AI into performing legitimate-seeming tasks, attackers can leak sensitive data without triggering security alerts.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
A while back at sat down with me and dropped some of the best AI hacking knowledge that I've ever put out on this channel and you guys loved it. >> And that's where you'll find a load of chat bots. They will like specifically not render markdown as like a security mitigation. >> But there was one comment that I kept seeing over and over and that was cool, but show us the actual work. Show us a real payload. How did he do it? So I brought him back and this time he didn't just talk. He built a full replica of one of his favorite real world bugs so we could break it down live on camera with him walking us through every step. And here's a setup. There is an online store with an AI chatbot. You got 50 bucks in your wallet. The thing that you want to buy costs over 10 and something change and yo…