Skip to content
Back to the blog
Artificial intelligence September 24, 2026 · 1 min read

A single email was enough to take over Manus, the AI agent valued at $4 billion

Salt Labs researchers have disclosed a prompt injection vulnerability in Manus, an AI agent app raising funds at a $4 billion valuation. The attack was surprisingly simple: all it took was sending the victim an email with hidden instructions that Manus would later read when checking their inbox. To get past the security filter, the researchers encoded the commands with a JavaScript obfuscation technique called JSFuck, so the code ran before the warning was triggered.

This let them run code remotely inside someone else’s account and find the credentials and tokens for connected apps such as Gmail, Google Drive or GitHub. Manus didn’t respond to the report, but Meta’s bug bounty programme confirmed and fixed the problem. The case is a reminder that AI apps that read external data, such as emails or websites, need very rigorous security filters: any text they process can become a command.

Tip from Soporte Informático 360

Before connecting an AI agent to your email, storage or repositories, think about what it could do if someone gave it hidden instructions. Grant only the permissions it truly needs, revoke access you don’t use and don’t trust it with accounts holding sensitive information without supervision.

Source: Dark Reading. Summary prepared by our team for informational purposes.

Related service

IT maintenance for businesses

Preventive and corrective maintenance of your equipment to avoid downtime and extend its useful life.