🛡 Scammers are seizing domains from AI 'hallucinations'
Cybercriminals pre-register non-existent domains and package names that LLMs regularly hallucinate in their responses. By trusting the AI, people end up on phishing sites or install poisoned packages. According to Unit 42, out of 2.1 million generated URLs, 13,229 domains are already malicious, and another ~250,000 are available for seizure.
🌍 LLMs have become an attack delivery channel: bots follow links generated by the model itself, and new domains bypass blocklists — they have no history. Monitoring model 'blind spots' predicts such registrations 18–51 days in advance.
👤 A link or package name from a bot's response is not a guarantee of safety. Check them yourself: official websites, PyPI and npm registries.
Source 1: https://spectrum.ieee.org/ai-cyberattacks-llm-slop-squatting Source 2: https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/
