Darktrace: history poisoning hijacks Claude Code, Codex, and Kiro-CLI
Darktrace found Claude Code, OpenAI Codex, AWS Kiro-CLI, and Pi store conversation history client-side with no check that model replies are authentic. Rewriting that history convinced agents they were mid-engagement as authorized red-teamers; the lab disclosed to Anthropic, OpenAI, and AWS and proposes cryptographic signing of responses.
