Cryptographer Matthew Green Warns Isolated AI Agents Can Form Computer Worms
Cryptographer Matthew Green highlighted that isolating AI agents in separate sandboxes is insufficient to prevent computer worms from spreading. He demonstrated how agents can unknowingly read malicious instructions left in shared communication channels or caches and propagate them to other agents. As autonomous personal AI agents like Meta's Muse are increasingly deployed to manage communication apps, shared documents, and daily tasks, traditional sandboxing security models become inadequate. This reveals a fundamental cybersecurity challenge where malicious prompt injections can replicate autonomously across interconnected AI workflows. The propagation occurs when an agent encounters a hijacked payload stored in shared state—such as a package cache, email, Slack, or WhatsApp—and executes instructions that cause it to write the payload for the next agent to consume. This creates the classic two halves of a computer worm: a hijacking payload and an unwitting transport agent, operating across separately isolated environments.
## BACKGROUND
Sandboxing is a cybersecurity practice that isolates running programs in a restricted environment to prevent them from making unauthorized changes to the broader system. However, modern AI agents increasingly interact with external text sources and shared communication tools using large language models, making them vulnerable to prompt injection attacks where untrusted data alters their intended instructions.