{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/findings/attempts-multiply-hijack-success/",
 "asOf": "2026-09-26",
 "id": "attempts-multiply-hijack-success",
 "claim": "Measured hijack rates rise sharply when attackers get repeated attempts, so single-attempt figures understate risk.",
 "evidenceKind": "measured",
 "scope": "Depends on attack budget and model; figures come from lab and government red-teaming.",
 "topics": [
  "prompt-injection",
  "eval-validity"
 ],
 "atlas": [],
 "evidence": [
  {
   "event": "us-aisi-agent-hijacking-evaluations-2025",
   "note": "Claude 3.5 Sonnet, five new injection tasks: average success rose from 57% at one attempt to 80% with 25 attempts."
  },
  {
   "event": "anthropic-opus-4-6-system-card-prompt-injection-2026",
   "note": "Computer use, Opus 4.6 with extended thinking and no safeguards: 17.8% at 1 attempt versus 78.6% at 200 attempts."
  },
  {
   "event": "gray-swan-agent-red-teaming-competition-2025"
  }
 ],
 "relations": [
  {
   "type": "supports",
   "target": "adaptive-attacks-defeat-published-defenses",
   "note": "Both show fixed, single-shot attack measurements understate attacker success; the attempt data comes from frontier models, not the published research defenses."
  },
  {
   "type": "qualifies",
   "target": "lab-defenses-reduce-not-eliminate",
   "note": "Where labs quote single-attempt rates, they understate a persistent attacker: Opus 4.6 computer-use success rose from under 18% at 1 attempt to up to 78.6% at 200."
  }
 ],
 "statusHistory": [
  {
   "status": "reported",
   "on": "2025-01-17",
   "why": "US AISI reports success rising with attempts.",
   "event": "us-aisi-agent-hijacking-evaluations-2025",
   "kind": "evidence"
  },
  {
   "status": "corroborated",
   "on": "2026-02-05",
   "why": "Anthropic reports multi-attempt rates in a system card.",
   "event": "anthropic-opus-4-6-system-card-prompt-injection-2026",
   "kind": "evidence"
  }
 ],
 "halfLifeDays": 540,
 "wouldChange": "Evidence that success saturates after a few attempts for current defenses.",
 "fideQuestions": [],
 "methods": [
  "adaptive-red-teaming",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}