Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

AgentFlayer: poisoned document leaks API keys through ChatGPT Connectors

Zenity Labs showed that a shared Google Drive document with hidden white text could make ChatGPT search a user's Drive for API keys and send them to an attacker via an image URL, with no user interaction beyond the share.

Occurred 1 June 2025 · Disclosed 6 August 2025 · Record updated 13 September 2026

Impact

Any secrets stored in a connected Drive could be exfiltrated. OpenAI deployed mitigations after disclosure.

Our coverage

Sources

  1. labs.zenity.iohttps://labs.zenity.io/p/agentflayer-chatgpt-connectors-0click-attack
  2. wired.comhttps://www.wired.com/story/poisoned-document-could-leak-secret-data-via-chatgpt/