← Back to feed
AI SecurityEmerging1 sourceAug 9, 2025 · 10:00via Embrace The Red (AI agent security)

OpenHands and the Lethal Trifecta: How Prompt Injection Can Leak Access Tokens

Brief

Another day, another AI data exfiltration exploit. Today we talk about OpenHands , formerly referred to as OpenDevin. It’s created by All-Hands AI.

The OpenHands agent renders images in chat, which enables zero-click data exfiltration.

Simon Willison recently gave this data exfiltration attack pattern a great name: Lethal Trifecta .

We discuss this specific image based attack technique frequently. Sometimes a message must be repeated multiple times to raise awareness and become mainstream knowledge.

Read more on Embrace The Red (AI agent security)