Briefing

Agentic Traps: Hidden Tokens and Dynamic Cloaking Threaten AI Agents

security
by Roger Montti ·

Audit web content for hidden tokens and dynamic cloaking that could trap AI agents and mitigate potential security risks.

What to do now

Audit web content for hidden tokens and dynamic cloaking that could trap AI agents and mitigate potential security risks.

Summary

Agents that navigate the web rely on the raw page format, but malicious actors can embed hidden tokens that are invisible to humans yet alter an agent’s goals or induce jailbreaking. Dynamic cloaking allows a site to present different content to AI agents than to human visitors, based on detected interaction patterns, effectively creating a prompt injector that can redirect agents toward malicious actions. These traps can grant attackers access to wallets or other sensitive resources, as agents may be given permissions they did not intend. The traps exploit the fact that AI agents process the page’s underlying markup rather than visual rendering, making hidden tokens and cloaked content difficult to detect. Recent reports show that hidden tokens can change an agent’s objective, while dynamic cloaking can manipulate the agent’s reasoning process. As AI agents become the majority of HTML traffic, the surface area for such attacks expands, threatening both user safety and system integrity. Web developers must audit content for hidden tokens, dynamic cloaking, and other deceptive practices to mitigate the risk of agentic traps. Protecting the web environment requires proactive safeguards and continuous monitoring of AI agent interactions.

Key changes

  • Hidden tokens invisible to humans can alter AI agent goals or induce jailbreaking.
  • Dynamic cloaking presents different content to AI agents based on interaction patterns.
  • Traps can grant attackers access to wallets or sensitive resources.
  • AI agents process raw markup, making hidden tokens hard to detect.
  • Hidden tokens can change agent objectives; dynamic cloaking manipulates reasoning.
  • AI agents now majority of HTML traffic, expanding attack surface.
  • Web developers must audit for hidden tokens and dynamic cloaking.
  • Continuous monitoring of AI agent interactions is required.

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting