Skip to content

Build1 publisher2 min readPublished

Hidden Unicode traps on signup forms turn prompt injection against AI agents

Forums are hiding invisible Unicode prompt-injection traps on signup pages to make AI agents give themselves away, according to a dev.to post. Teams running browsing agents now have to defend against hostile page text from site operators, not only from attackers.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Hidden Unicode traps on signup forms turn prompt injection against AI agents
Generated illustration

What happened

  • An AI agent emailed security writer Bruce Schneier to tell him about the hidden Unicode traps that websites were setting for it.
  • A human filling out the signup form never sees the hidden text, while a bot that ingests the page DOM and follows embedded instructions does.
  • The post presents the traps as an alternative to CAPTCHAs, which annoy humans and get solved by bot farms anyway.
  • The author puts the technique in a known defensive category alongside steganographic traps, honeypot fields and hidden form inputs that only bots fill in.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure A browsing agent that passes raw page text to its model can now be identified and blocked by the sites it visits, through the same input path an attacker would use to hijack it.
  • constraint Sites that rely on these traps get detection that catches careless harnesses only, and by the author's account it will neither last long nor stop a well-built agent.
  • constraint Operators who want prompt-level traps will mostly have to build them in-house for now, because the author says most WAF vendors lack the skill set.
  • exposure Payloads aimed at agents also reach accessibility tools and search crawlers, and nobody has settled who is liable when one of those trips a trap.

The post says sites are "apparently" doing this [2]. It does not name a forum or reproduce a payload. The pattern it describes is specific all the same. The sites plant hidden prompt-injection text, including invisible Unicode steganography, so that an agent outs itself or fails partway through signup [2]. "That's a legitimately clever bit of judo," the author wrote [4].

The trap depends on one harness habit. The agent fetches a page, takes the raw DOM text and feeds it into the prompt without filtering out invisible characters or suspicious encoding [7]. The model then follows whatever instructions it finds, because current agents parse and obey text they should not trust [6]. The author's verdict on that kind of harness is short: "you've already lost" [7].

The Schneier email is the post's hook [1]. As bug reports go, it was at least sent to the right person [1]. The author does not treat it as evidence of agency, writing that "these systems don't have concerns, they have context windows and whatever behavior their operator's harness encourages" [8].

On the agent side, the defence is ordinary prompt-injection hygiene. Treat all ingested page content, hidden or visible, as untrusted input, and filter out invisible characters before page text reaches the model [7]. Once builders do that, the author expects the traps to stop working. The post compares the cycle to every CAPTCHA generation before it [6].

I think that advice is right for any team whose agents browse arbitrary sites. An attacker's injected instructions and a forum's detection payload come in through the same channel, so one input filter blocks both [7][6]. That still leaves the operator a decision. A forum that plants these traps is trying to keep bots out, and whether the agent should keep signing up there is a policy question [2].

What to watch

  • A named forum or site publishing the actual payload it plants would move this from a single post's 'apparently' to a documented practice.
  • Agent frameworks shipping default filters for invisible Unicode in page text would disarm the current generation of signup traps.
  • Anti-bot or WAF vendors adding prompt-level traps to their products would put the technique on sites that never write it themselves.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories