AdaLCPI Attack Reconstructs Indirect Prompt Injections from Fragments
September 30, 2026
The AdaLCPI attack demonstrates that agents can reconstruct malicious objectives from incomplete, distributed fragments embedded in long-context retrieved content. This method uses adaptive search and OpenEvolve to iteratively refine fragments until the target agent successfully executes the reconstructed instruction.
HOW THIS AFFECTS YOU
●
builderYou must implement more robust verification for agentic tool-use to prevent fragmented prompt injections.
●
policyThis highlights a critical safety gap in how long-context reasoning increases vulnerability to indirect attacks.