Skip to main content
Security

Prompt Injection Just Got Classified as Malware

Take Interest Inc. · · 5 min read

Field Guide

Prompt Injection Just Got Classified as Malware

Researchers want prompt injection reclassified as malware. A $40K bounty from UK AISI, OpenAI, and Anthropic is testing why.

ai-security runtime-protection governance

Key takeaway

Researchers are formalizing 'promptware'—a new classification that treats prompt injection attacks as actual malware, with kill chains that mirror traditional multi-stage exploits

Key takeaway

A $40K bounty running Feb 25 - Mar 11, 2026 (UK AISI, OpenAI, Anthropic, Amazon, Meta, Google DeepMind) proves the threat is real enough to fund research against actual frontier models

Key takeaway

Success rates exceed 85% against state-of-the-art defenses, and OWASP lists prompt injection as the #1 risk for LLM applications—but the industry still treats it like a chatbot insult problem