Prompt Leakage and System Prompt Extraction in Commercial LLM Applications
Two-turn attacks raise prompt leakage success rates to 86 percent across leading models.
Svetlana Prochazka
Staff Researcher & Writer
A former cryptographic engineer who worked on protocol design for a European fintech firm, Svetlana now translates dense cryptographic theory into actionable analysis for security practitioners and developers alike.
6 stories
Two-turn attacks raise prompt leakage success rates to 86 percent across leading models.
Attackers can recover secrets one character at a time by measuring response delays.
Attackers exploit weak reset flows to bypass MFA and take over accounts without cracking passwords.
Attackers now bypass MFA by stealing session tokens after users legitimately log in.
Attackers forge tokens by controlling which verification algorithm runs.
Stolen session tokens now beat passwords as the primary credential attack.